PT-2019-7741 · WordPress · Post Indexer

Glyn Wintle

·

Published

2019-09-13

·

Updated

2019-09-13

·

CVE-2016-10948

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Post Indexer plugin versions prior to 3.0.6.2 for WordPress
Description The issue is related to incorrect handling of data passed to the unserialize function. This can potentially lead to security issues.
Recommendations For versions prior to 3.0.6.2, update to version 3.0.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the unserialize function until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10948

Affected Products

Post Indexer