wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-09-12T10:00:00
Updated: 2024-08-06T16:38:01.927Z
Reserved: 2013-06-12T00:00:00
Link: CVE-2013-4338
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-09-12T13:28:37.443
Modified: 2024-11-21T01:55:22.787
Link: CVE-2013-4338
Redhat
No data.