What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.
Explanation of Vulnerability in Simple Terms
The HTML5 SoundCloud Player with Playlist Free plugin through version 2.8.0 deserializes untrusted data without validation. An authenticated administrator can craft a malicious serialized object to execute arbitrary PHP code on the site. This requires admin-level access but can lead to complete site compromise.
What an attacker can do
Run arbitrary PHP code on the site with full privileges.
Potential impact on your site
A compromised admin account can execute code, modify content, steal data, or take the site offline.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities