CVE-2023-1549: Ad Inserter < 2.7.27 - Admin+ PHP Object Injection
The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1549?
CVE-2023-1549 is a vulnerability in the Ad Inserter WordPress plugin before version 2.7.27 that allows high privilege users to perform PHP Object Injection.
How does CVE-2023-1549 occur?
CVE-2023-1549 occurs when the plugin unserializes user input provided via the settings, allowing for PHP Object Injection.
What is the severity of CVE-2023-1549?
CVE-2023-1549 has a severity rating of 7.2, which is considered high.
How can the CVE-2023-1549 vulnerability be exploited?
The CVE-2023-1549 vulnerability can be exploited by high privilege users, such as admins, who have access to the plugin settings.
How do I fix the CVE-2023-1549 vulnerability?
To fix the CVE-2023-1549 vulnerability, update your Ad Inserter WordPress plugin to version 2.7.27 or later.