PublishPress Capabilities <= 2.5.1 - Authenticated (Administrator+) PHP Object Injection
highThe PublishPress Capabilities plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.1 via deserialization of untrusted input when processing an import file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a...
- CVSS:
- 7.2
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Oct 10, 2022