PHP Object Injection Vulnerability in Splashing Images Plugin for WordPress
CVE-2018-6195
7.2HIGH
What is CVE-2018-6195?
The Splashing Images plugin for WordPress contains a vulnerability that allows authenticated users (administrators, editors, or authors) to perform PHP Object Injection attacks. This is achieved through manipulated serialized data sent via the 'session' HTTP GET parameter to the wp-admin/upload.php endpoint, potentially compromising the site's integrity. It is crucial for users of the plugin to update to version 2.1.1 or later to mitigate this vulnerability.