← back
CVE-2023-0232

ShopLentor < 2.5.4 - PHP Object Injection

CVSS 9.8 CRITICALEPSS 3.3%
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 3.3%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
21 Feb 2023Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · ShopLentor
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →