What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
Explanation of Vulnerability in Simple Terms
The WordPress Assistant plugin for Beaver Builder contains a deserialization vulnerability in versions up to 1.5.1. An authenticated administrator can supply malicious serialized data that the plugin processes without validation, potentially leading to arbitrary code execution on the site. This requires administrator-level access to exploit.
What an attacker can do
Run arbitrary PHP code on the site with administrator privileges.
Potential impact on your site
A compromised admin account can fully control your site, including installing malware or stealing data.
Conditions required to exploit
Attacker must have administrator access to the WordPress site.
Key dates
External resources
Related vulnerabilities