ToTop Link <= 1.7.1 - Unauthenticated PHP Object Injection

2021-11-15 00:00
Muhammed Kara

Strategic Overview

Status
Unpatched
Affected PluginToTop Link
Affected Version<= 1.7.1
CVSS9.0Critical
CVECVE-2021-24857
View all ToTop Link vulnerabilities

Vulnerability Overview

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C