Modal Survey <= 2.0.1.8 - PHP Object Injection
critical
The Modal Survey plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1.8 via deserialization of untrusted input using the unserialize() function. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to remotely t...
- CVSS:
- 9.1
- Affected:
- up to 2.0.1.8
- Fixed in:
- 2.0.1.8.2
- Disclosed:
- Jan 8, 2021
Modal Survey < 2.0.1.8.2 - Authorization Bypass
high
The Modal Survey Plugin for WordPress is vulnerable to Arbitrary Survey Update, Deletion and Creation in versions before 2.0.1.8.2 via the 'ajax_survey' AJAX action due to lacking capability checks. This allows unauthenticated attackers to create, update, or delete arbitrary surveys.
- CVSS:
- 7.5
- Affected:
- up to 2.0.1.8.2
- Fixed in:
- 2.0.1.8.2
- Disclosed:
- Jan 8, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database