PT-2026-22463 · WordPress · Super Stage Wp
Publicado
2026-02-28
·
Atualizado
2026-02-28
·
CVE-2026-1542
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Super Stage WP WordPress plugin versions through 1.0.1
Description
The software allows unauthenticated users to perform PHP Object Injection. This is possible because the software unserializes user input via REQUEST when a suitable gadget is present. The issue could allow for malicious code execution.
Recommendations
Update the Super Stage WP WordPress plugin to a version later than 1.0.1.
Exploit
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Super Stage Wp