Woodmart Core <= 1.0.36 - Authentication Bypass to Privilege Escalation
critical
The Woodmart Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in its social login functionality in versions up to, and including, 1.0.36. This makes it possible for unauthenticated attackers to supply a valid payload to the 'opauth' parameter and authenticate as any user on...
- CVSS:
- 9.8
- Affected:
- up to 1.0.36
- Fixed in:
- 1.0.37
- Disclosed:
- May 11, 2023
CVE-2023-32244 on NVD →
Woodmart Core <= 1.0.36 - PHP Object Injection
critical
The Woodmart Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.36 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. If a POP chain is present in the vulnerable plugin, an additional plugin or theme installed on the t...
- CVSS:
- 9.8
- Affected:
- up to 1.0.36
- Fixed in:
- 1.0.37
- Disclosed:
- May 11, 2023
CVE-2023-32242 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database