Analytics Stats Counter Statistics <= 1.2.2.5 - Unauthenticated PHP Object Injection
criticalThe Analytics Stats Counter Statistics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2.5 via deserialization of untrusted input in the vulnerable function wpadm_unpack. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain...
- CVSS:
- 9.8
- Affected:
- up to 1.2.2.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 1, 2017