PHP Object Injection Vulnerability in Link Whisper Free Plugin for WordPress
CVE-2024-2693
Summary
The Link Whisper Free plugin for WordPress has a vulnerability that allows for PHP Object Injection, exposing all versions up to and including 0.7.1. This vulnerability arises from the deserialization of untrusted input in the 'mfn-page-items' post meta value, making it possible for authenticated users with contributor-level access or higher to exploit this flaw. Although no known PHP Object Pollution (POP) chain exists within the vulnerable plugin itself, it is critical to note that if a POP chain is established through other plugins or themes present on the WordPress site, attackers could potentially delete arbitrary files, access sensitive information, or execute malicious code. Site administrators using vulnerable versions should prioritize immediate updates to safeguard against possible exploitation.
Affected Version(s)
Link Whisper Free * <= 0.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved