CVE-2023-0232: ShopLentor < 2.5.4 - PHP Object Injection
Published Feb 21, 2023
·Updated
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
Affected Software
1 affected component
HasThemes Shoplentor Wordpress<2.5.4
Remediation
Event History
Feb 21, 2023
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-0232?
CVE-2023-0232 is a vulnerability in the ShopLentor WordPress plugin before version 2.5.4 that allows PHP object injection.
2
How does CVE-2023-0232 impact the ShopLentor plugin?
CVE-2023-0232 allows an attacker to unserialize user input from cookies in order to track viewed products and user data, potentially leading to PHP object injection.
3
Is CVE-2023-0232 a critical vulnerability?
Yes, CVE-2023-0232 is rated as critical with a severity score of 9.8.
4
How can I fix CVE-2023-0232?
To fix CVE-2023-0232, you should update the ShopLentor WordPress plugin to version 2.5.4 or later.
5
Where can I find more information about CVE-2023-0232?
You can find more information about CVE-2023-0232 on the WordPress plugin's Trac page and the WPScan vulnerability report.