Description


The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Weaknesses


Could not find any weaknesses

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.2 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-23T14:15:13.797Z

3 years ago

Last modified

2025-04-02T14:15:21.210Z

11 months ago