CVE-2023-1347: Customizer Export/Import < 0.9.6 - Admin+ PHP Object Injection
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1347?
CVE-2023-1347 is a vulnerability in the Customizer Export/Import WordPress plugin that allows high privilege users to perform PHP Object Injection.
What is the severity of CVE-2023-1347?
The severity of CVE-2023-1347 is high with a CVSS score of 7.2.
How does CVE-2023-1347 affect Fastlinemedia Customizer Export/Import?
Fastlinemedia Customizer Export/Import plugin version up to 0.9.6 is affected by CVE-2023-1347.
What is PHP Object Injection?
PHP Object Injection is a vulnerability that allows an attacker to inject malicious PHP objects into an application, leading to various exploits.
How can I fix CVE-2023-1347?
Update the Customizer Export/Import WordPress plugin to version 0.9.6 or higher to fix CVE-2023-1347.