PHP Object Injection Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin for WordPress
CVE-2024-2006
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 March 2024
Summary
The Post Grid, Slider & Carousel Ultimate plugin for WordPress is susceptible to a PHP Object Injection vulnerability due to the insecure deserialization of untrusted inputs within the outpost_shortcode_metabox_markup function. This vulnerability is present in all versions up to and including 1.6.7. Authenticated attackers, holding contributor-level permissions or higher, may exploit this flaw to inject a malicious PHP object. When combined with other plugins or themes that exhibit a PHP Object Pattern (POP) chain, this vulnerability could potentially enable attackers to perform a variety of harmful actions, including deleting arbitrary files, accessing sensitive information, or executing arbitrary code on the WordPress site.
Affected Version(s)
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget * <= 1.6.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved