1 results (0.005 seconds)

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2025 — The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP... • https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L602 • CWE-502: Deserialization of Untrusted Data •