Lucene search

K
wpvulndbWpvulndbWPVDB-ID:6269AA9E-31F2-4893-94CC-36D7FD20D996
HistoryAug 08, 2022 - 12:00 a.m.

String Locator < 2.6.0 - Authenticated PHAR Deserialization

2022-08-0800:00:00
wpscan.com
13
string locator
authenticated
phar deserialization
unvalidated parameters
gadget chain
admin

EPSS

0.002

Percentile

57.0%

The plugin does not validate a parameter, which could lead to PHAR deserialisation when an attacker manage to upload a malicious file crafted with a suitable gadget chain and having a logged in admin open a malicious link

EPSS

0.002

Percentile

57.0%

Related for WPVDB-ID:6269AA9E-31F2-4893-94CC-36D7FD20D996