What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.
Explanation of Vulnerability in Simple Terms
WishList Member X versions up to 3.29.0 contain a deserialization vulnerability that allows authenticated users to execute arbitrary PHP code on the site. An attacker with a low-privilege account can craft malicious serialized data to trigger code execution without user interaction. This affects the core functionality of the membership plugin and poses a severe risk to site integrity and data confidentiality.
What an attacker can do
Run arbitrary PHP code on the site with the privileges of the web server.
Potential impact on your site
Attackers with member accounts can compromise your entire site, steal data, and modify content.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or member role).
Key dates
External resources
Related vulnerabilities