MarketPress <= 3.2.6 - Unauthenticated PHP Object Injection
criticalThe MarketPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2.6 via deserialization of untrusted input mp_globalcart_* cookie value. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitra...
- CVSS:
- 9.8
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.7
- Disclosed:
- Oct 1, 2017