WordPress Plugin Vulnerabilities

Visualizer: Tables and Charts Manager for WordPress < 3.7.10 - Contributor+ PHAR Deserialization

Description

The plugin does not validate the ‘remote_data’ parameter allowing contributor and above roles to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP objects when a POP chain is present.

Affects Plugins

Fixed in 3.7.10

References

Classification

Miscellaneous

Original Researcher
Rasoul Jahanshahi
Verified
Yes

Timeline

Publicly Published
2022-07-05 (about 3 years ago)
Added
2022-07-05 (about 3 years ago)
Last Updated
2023-04-10 (about 3 years ago)

Other