CVE-2023-0232

CVE-2023-0232: ShopLentor < 2.5.4 - PHP Object Injection

Vendor Unknown
Product ShopLentor
Published February 21, 2023
Last update March 12, 2025

CVSS base score

What the vulnerability does

01Description

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

Key dates

02Disclosure timeline

February 21, 2023 CVE published
March 12, 2025 Record updated