WordPress Plugin Vulnerabilities

User Registration < 2.3.3 - Subscriber+ PHP Object Injection

Description

The plugin unserializes user input via the ur_get_user_extra_fields and user_registration_form_field function, which could allow any authenticated users, such as subscriber to perform PHP Object Injection when a suitable gadget is present on the blog

Affects Plugins

Fixed in 2.3.3

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Rafie Muhammad
Verified
No

Timeline

Publicly Published
2023-03-21 (about 3 years ago)
Added
2023-04-06 (about 3 years ago)
Last Updated
2023-04-06 (about 3 years ago)

Other