8.8
CVE-2023-6528
- EPSS 1.37%
- Veröffentlicht 08.01.2024 19:15:10
- Zuletzt bearbeitet 03.06.2025 15:15:51
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE
Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Mögliche Gegenmaßnahme
Slider Revolution: Update to version 6.6.19, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themepunch ≫ Slider Revolution SwPlatformwordpress Version < 6.6.19
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Slider Revolution
Version
[*, 6.6.19)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.37% | 0.683 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb
https://www.wordfence.com/threat-intel/vulnerabilities/id/951e3497-8fbc-4cc9-a784-edf7bb679175