Description
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12316 | The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection. |
References
History
Wed, 12 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-12T20:48:45.543Z
Reserved: 2023-01-12T10:31:18.880Z
Link: CVE-2023-0232
Updated: 2024-08-02T05:02:44.037Z
Status : Modified
Published: 2023-02-21T09:15:12.107
Modified: 2025-03-12T21:15:40.023
Link: CVE-2023-0232
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD