Description
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23637 | The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution. |
References
History
Tue, 11 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-11T17:21:25.629Z
Reserved: 2023-03-13T19:25:08.399Z
Link: CVE-2023-1381
Updated: 2024-08-02T05:49:10.358Z
Status : Modified
Published: 2023-04-10T15:15:07.237
Modified: 2025-02-11T18:15:21.000
Link: CVE-2023-1381
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD