Advanced Post Manager <= 4.5.1 - PHP Object Injection
criticalThe Advanced Post Manager for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.1 via deserialization of untrusted input from the parameter saved_filter. This allows attackers to inject a PHP Object.
- CVSS:
- 9.8
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.2
- Disclosed:
- Jul 15, 2022