The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-06-07T01:51:46.527Z

Updated: 2023-06-07T01:51:46.527Z

Reserved: 2023-06-06T13:21:47.283Z


Link: CVE-2020-36726

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-06-07T02:15:12.617

Modified: 2023-11-07T03:22:30.007


Link: CVE-2020-36726

JSON object: View

cve-icon Redhat Information

No data.

CWE