PT-2024-14995 · WordPress · Slider Revolution

Prajyot Chemburkar

+1

·

Published

2024-01-08

·

Updated

2024-01-11

·

CVE-2023-6528

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slider Revolution WordPress plugin versions prior to 6.6.19
Description The issue allows users with at least the Author role to unserialize arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Recommendations For versions prior to 6.6.19, update to version 6.6.19 or later to resolve the issue. As a temporary workaround, consider restricting the import slider functionality to users with higher roles than Author until the update is applied.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-6528

Affected Products

Slider Revolution