Post Indexer <= 3.0.6.1 - PHP Object Injection
highThe Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
- CVSS:
- 8.1
- Affected:
- up to 3.0.6.2
- Fixed in:
- 3.0.6.2
- Disclosed:
- Nov 17, 2016
plugin
2 known security issues reported for the Post Indexer WordPress plugin. Most recent disclosed Nov 17, 2016.
Running Post Indexer on your site? Check whether your installed version is affected.
Scan your site freeThe Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free