CVE-2020-36726: Ultimate Reviews < 2.1.33 - PHP Object Injection
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Ultimate Reviews plugin for WordPress vulnerability?
The vulnerability ID is CVE-2020-36726.
What is the severity rating of CVE-2020-36726?
The severity rating of CVE-2020-36726 is 9.8 (critical).
What is the affected software of CVE-2020-36726?
The affected software is the Ultimate Reviews plugin for WordPress version up to and including 2.1.32.
How can an attacker exploit CVE-2020-36726?
An unauthenticated attacker can exploit CVE-2020-36726 by injecting a PHP Object via deserialization of untrusted input.
Are there any patches or fixes available for CVE-2020-36726?
Yes, a fix has been released. It is recommended to update the Ultimate Reviews plugin for WordPress to the latest version to address the vulnerability.