What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.
Explanation of Vulnerability in Simple Terms
The HTML5 MP3 Player with Playlist Free plugin through version 3.0.0 deserializes untrusted data without validation. An authenticated administrator can craft a malicious serialized object to execute arbitrary PHP code on the site. This requires admin-level access and affects the entire site, not just the plugin.
What an attacker can do
Run arbitrary PHP code on the site with full site privileges.
Potential impact on your site
A compromised admin account can take complete control of your site, steal data, or inject malware.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities