ZeroHour

CVE-2023-6049

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p59
Published
()
Modified
Description

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

Vendors
estatik
Products
estatik
Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.