CVE-2023-1669: SEOPress < 6.5.0.3 - Admin+ PHP Object Injection
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1669?
CVE-2023-1669 has been assigned a high severity due to the potential for PHP Object Injection vulnerabilities.
How do I fix CVE-2023-1669?
You can fix CVE-2023-1669 by updating the SEOPress WordPress plugin to version 6.5.0.3 or later.
Who is affected by CVE-2023-1669?
CVE-2023-1669 affects users of the SEOPress WordPress plugin prior to version 6.5.0.3.
What is PHP Object Injection in relation to CVE-2023-1669?
PHP Object Injection allows an attacker to exploit vulnerable code by injecting objects in the context of a PHP application, leading to remote code execution.
Can high-privilege users exploit CVE-2023-1669?
Yes, high-privilege users such as admin can exploit CVE-2023-1669, potentially causing significant security issues.