Theme per user <= 1.0.1 - Unauthenticated PHP Object Injection
criticalThe Theme per user plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.2 (exclusive) via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an ad...
- CVSS:
- 9.8
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.2
- Disclosed:
- Dec 29, 2023