Glossary by WPPedia <= 1.3.0 - Authenticated (Administrator+) PHP Object Injection
highThe Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated attackers, with Administrator-level access a...
- CVSS:
- 7.2
- Affected:
- up to 1.3.0
- Fix:
- No patched version reported
- Disclosed:
- May 20, 2025