CVE-2023-3392

CVE-2023-3392: Read More & Accordion < 3.2.7 - Admin+ PHP Object Injection

Vendor Unknown
Product Read More & Accordion
Published October 16, 2023
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Key dates

02Disclosure timeline

October 16, 2023 CVE published
September 16, 2024 Record updated