Unseen Blog Theme Vulnerable to PHP Object Injection
CVE-2024-7432
Summary
The Unseen Blog theme for WordPress is subject to a PHP Object Injection vulnerability, which affects all versions up to and including 1.0.0. This flaw arises from the deserialization of untrusted input, potentially enabling authenticated attackers with Contributor-level access or higher to inject PHP objects. Although the vulnerable software does not currently exhibit a known Payload Object Pollution (POP) chain, if an additional plugin or theme is installed that provides such a chain, attackers can exploit the vulnerability. This could lead to severe consequences, including the ability to delete arbitrary files, access sensitive data, or execute malicious code on the affected system.
Affected Version(s)
Unseen Blog * <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved