What the vulnerability does
01Description
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
Explanation of Vulnerability in Simple Terms
Betheme version 26.5.1.4 and earlier contains a vulnerability allowing authenticated users with low privileges to read, modify, or delete data on the site. The vulnerability requires a valid user account but no special permissions. Site administrators should update to a version newer than 26.5.1.4 to remediate the issue.
What an attacker can do
Read, modify, or delete site data with a low-privilege user account.
Potential impact on your site
Any registered user can access, change, or remove sensitive site data without authorization.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the WordPress site.
Key dates
External resources