PHP Object Injection Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin for WordPress
CVE-2024-2006

8.8HIGH

Summary

The Post Grid, Slider & Carousel Ultimate plugin for WordPress is susceptible to a PHP Object Injection vulnerability due to the insecure deserialization of untrusted inputs within the outpost_shortcode_metabox_markup function. This vulnerability is present in all versions up to and including 1.6.7. Authenticated attackers, holding contributor-level permissions or higher, may exploit this flaw to inject a malicious PHP object. When combined with other plugins or themes that exhibit a PHP Object Pattern (POP) chain, this vulnerability could potentially enable attackers to perform a variety of harmful actions, including deleting arbitrary files, accessing sensitive information, or executing arbitrary code on the WordPress site.

Affected Version(s)

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget * <= 1.6.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.