Row Seats Core < 2.68 - PHP Object Injection
highThe Row Seats Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.66 via deserialization of untrusted input from several parameters such as 'mycartitems'. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is pre...
- CVSS:
- 7.2
- Affected:
- up to 2.68
- Fixed in:
- 2.68
- Disclosed:
- Feb 14, 2017