bbPress Move Topics <= 1.1.4 - PHP Object Injection
2018-03-11 00:00
AnonymousStrategic Overview
StatusPatched in 1.1.6
Affected PluginbbPress Move Topics
Affected Version
<= 1.1.4CVSS8.8High
CVE
CVE-2018-21005Vulnerability Overview
The bbPress Move Topics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.4 via deserialization of untrusted input via the 'aforums_move_topics_page()' function where it passes the decoded 'allforums' value through the 'unserialize()' function. This allows authenticated attackers to inject a PHP Object.
Technical Analysis
REMEDIATION: Update to version 1.1.6, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C