The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
References
Configurations
History
No history.
Information
Published : 2023-06-07 02:15
Updated : 2023-11-07 03:22
NVD link : CVE-2020-36726
Mitre link : CVE-2020-36726
CVE.ORG link : CVE-2020-36726
JSON object : View
Products Affected
etoilewebdesign
- ultimate_reviews
CWE
CWE-502
Deserialization of Untrusted Data