PT-2026-27831 · WordPress · Ancorathemes Melody
CVE-2026-22510
·
Publicado
2026-03-25
·
Atualizado
2026-03-30
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AncoraThemes Melody versions n/a through 1.6.3
Description
A flaw exists in the deserialization of untrusted data within AncoraThemes Melody melodyschool, potentially allowing for object injection. This issue could allow an attacker to inject malicious objects into the system.
Recommendations
Update AncoraThemes Melody to a version later than 1.6.3.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ancorathemes Melody