First published: Fri Jan 01 2021(Updated: )
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Post Grid | <2.0.73 | |
PickPlugins Team Showcase | <1.22.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-35938.
The severity of CVE-2020-35938 is high with a severity value of 8.8.
The affected software versions for CVE-2020-35938 are Post Grid plugin before 2.0.73 for WordPress and Team Showcase plugin before 1.22.16 for WordPress.
The CWE ID for CVE-2020-35938 is 502.
Remote authenticated attackers can exploit CVE-2020-35938 by injecting arbitrary PHP objects using insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX.