Advanced Post Manager <= 4.5.1 - PHP Object Injection
2022-07-15 00:00
AnonymousStrategic Overview
StatusPatched in 4.5.2
Affected PluginAdvanced Post Manager
Affected Version
<= 4.5.1CVSS9.8Critical
CVE
N/AVulnerability Overview
The Advanced Post Manager for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.1 via deserialization of untrusted input from the parameter saved_filter. This allows attackers to inject a PHP Object.
Technical Analysis
REMEDIATION: Update to version 4.5.2, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C