Description
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54807 | The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:14:56.611Z
Reserved: 2023-09-14T18:46:15.120Z
Link: CVE-2023-4971
No data.
Status : Modified
Published: 2023-10-16T20:15:17.403
Modified: 2025-04-23T17:16:48.337
Link: CVE-2023-4971
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD