CVE-2023-26326: Critical severity themekraft buddyforms vulnerability
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26326?
CVE-2023-26326 is a vulnerability found in the BuddyForms WordPress plugin versions prior to 2.7.8.
What is the severity level of CVE-2023-26326?
The severity of CVE-2023-26326 is critical with a CVSS score of 9.8.
How does CVE-2023-26326 affect BuddyForms WordPress plugin?
CVE-2023-26326 allows unauthenticated attackers to exploit an insecure deserialization issue in BuddyForms WordPress plugin versions prior to 2.7.8.
How can CVE-2023-26326 be fixed?
To fix CVE-2023-26326, it is recommended to update the BuddyForms WordPress plugin to version 2.7.8 or newer.
Where can I find more information about CVE-2023-26326?
More information about CVE-2023-26326 can be found at the following link: https://www.tenable.com/security/research/tra-2023-7