WordPress Plugin Vulnerabilities

WOOF - Products Filter for WooCommerce < 1.3.2 - Admin+ PHP Object Injection

Description

The plugin unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Proof of Concept

Affects Plugins

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
thinhnguyen1337
Submitter
thinhnguyen1337
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2023-01-11 (about 2 years ago)
Added
2023-01-11 (about 2 years ago)
Last Updated
2023-01-11 (about 2 years ago)

Other