CVE-2023-4971
EUVD-2023-5480716.10.2023, 20:15
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| weavertheme | weaver_xtreme_theme_support | 𝑥 < 6.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration