9.8
CVE-2020-36726
- EPSS 0.96%
- Veröffentlicht 07.06.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:30:10
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Ultimate Reviews < 2.1.33 - PHP Object Injection
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
Mögliche Gegenmaßnahme
Ultimate Reviews: Update to version 2.1.33, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Ultimate Reviews
Version
[*, 2.1.33)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Etoilewebdesign ≫ Ultimate Reviews SwPlatformwordpress Version <= 2.1.32
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.96% | 0.762 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| security@wordfence.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.