Vulnerability Description
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weavertheme | Weaver Xtreme Theme Support | < 6.3.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/421194e1-6c3f-4972-8f3c-de1b9d2bcb13ExploitThird Party Advisory
- https://wpscan.com/vulnerability/421194e1-6c3f-4972-8f3c-de1b9d2bcb13ExploitThird Party Advisory
FAQ
What is CVE-2023-4971?
CVE-2023-4971 is a vulnerability with a CVSS score of 7.2 (HIGH). The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malici...
How severe is CVE-2023-4971?
CVE-2023-4971 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4971?
Check the references section above for vendor advisories and patch information. Affected products include: Weavertheme Weaver Xtreme Theme Support.