CVE-2023-6528

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themepunch:slider_revolution:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:44

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb - Exploit, Third Party Advisory

11 Jan 2024, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:themepunch:slider_revolution:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb - () https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb - Exploit, Third Party Advisory
Summary
  • (es) El complemento Slider Revolution de WordPress anterior a 6.6.19 no impide que los usuarios con al menos el rol de Autor deserialicen contenido arbitrario al importar controles deslizantes, lo que podría provocar una ejecución remota de código.
First Time Themepunch slider Revolution
Themepunch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-502

08 Jan 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 19:15

Updated : 2024-11-21 08:44


NVD link : CVE-2023-6528

Mitre link : CVE-2023-6528

CVE.ORG link : CVE-2023-6528


JSON object : View

Products Affected

themepunch

  • slider_revolution
CWE
CWE-502

Deserialization of Untrusted Data