Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection
criticalThe Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme(...
- CVSS:
- 9.8
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Oct 2, 2017