Blog2Social <= 6.9.3 - PHP Object Injection
2022-04-05 00:00
AnonymousStrategic Overview
StatusPatched in 6.9.4
Affected PluginBlog2Social: Social Media Auto Post & Scheduler
Affected Version
<= 6.9.3CVSS8.5High
CVE
N/AVulnerability Overview
The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to the use of unserialize on user supplied input retrieved from the 'b2s-post-meta-box-best-time-settings' and 'assignList' parameters.
Technical Analysis
REMEDIATION: Update to version 6.9.4, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C