CVE

CVE-2024-6152

Severidad:
ALTA
Type:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
27/07/2024
Última modificación:
27/07/2024

Descripción

*** Pendiente de traducción *** The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untrusted input in the flipbox_builder_Flipbox_ShortCode function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.