ZeroHour

CVE-2020-36718

PoC
CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.

Vendors
ninjateam
Products
gpdr ccpa compliance support
Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.