HomeDefault status
affected
Any version
affected
Description
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version
Credits
yiğit ibrahim sağlam
WPScan
References
wpscan.com/...rability/d6e3041f-62e8-49ba-8806-59a1c07ec43d/