What the vulnerability does
01Description
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
CVSS base score
What the vulnerability does
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Explanation of Vulnerability in Simple Terms
Super Stage WP versions 1.0.1 and earlier contain an unknown vulnerability. Without access to the vendor's advisory or security details, the specific attack vector and impact cannot be determined. Site administrators should contact the vendor for clarification and apply any available patches immediately.
What an attacker can do
Unknown; insufficient vulnerability details provided.
Potential impact on your site
Unknown risk level; vendor clarification and patch status needed.
Conditions required to exploit
Unknown; insufficient vulnerability details provided.
Key dates
External resources