ZeroHour

CVE-2023-5340

PoC
CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

Vendors
fivestarplugins
Products
five star restaurant menu
Ecosystems
WordPress
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.