What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.
Explanation of Vulnerability in Simple Terms
WP Webhooks versions 3.3.8 and earlier contain a deserialization vulnerability that allows high-privilege users to execute arbitrary PHP code on the site. An attacker with administrator or equivalent access can craft malicious serialized data to trigger code execution. This affects all installations of the plugin up to version 3.3.8.
What an attacker can do
Run arbitrary PHP code on the site with full site privileges.
Potential impact on your site
A compromised admin account can fully compromise the site, steal data, or modify content.
Conditions required to exploit
Attacker must have high-level site access (administrator role or equivalent).
Key dates
External resources
Related vulnerabilities