What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
Explanation of Vulnerability in Simple Terms
Responsive Slider by MetaSlider versions up to 3.106.0 contain a deserialization vulnerability in how they process untrusted data. An authenticated administrator can craft malicious input that causes the plugin to deserialize and execute arbitrary code on the site. This requires high-level admin access but can lead to full site compromise.
What an attacker can do
Run arbitrary code on the site with the privileges of the web server.
Potential impact on your site
A compromised admin account can take over your entire site, steal data, or inject malware.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities