What the vulnerability does
01Description
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Explanation of Vulnerability in Simple Terms
Fluent Boards Pro versions up to 2.0.11 contain a deserialization vulnerability that allows high-privileged users to execute arbitrary code on the site. An attacker with admin or equivalent access can craft malicious serialized data to trigger unintended PHP execution. This affects confidentiality, integrity, and availability of the site.
What an attacker can do
Run arbitrary PHP code on the site with full admin privileges.
Potential impact on your site
A compromised admin account can fully compromise your site, steal data, modify content, or install backdoors.
Conditions required to exploit
Attacker must have high-level admin or equivalent access to the WordPress installation.
Key dates
External resources
Related vulnerabilities