CVE-2023-3360: Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection
Published Sep 2, 2026
·Updated
The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
Affected Software
1 affected component
WordPress plugin "Weaver Show Posts"<1.8.1
Event History
Sep 2, 2026
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high-privilege access to the WordPress site and must be able to import a malicious file through the plugin. Exploitation also requires a suitable PHP object gadget chain to be present on the blog.
2
What versions are affected?
Weaver Show Posts versions before 1.8.1 are affected.
3
What is the impact if exploitation succeeds?
The issue may allow PHP object injection. The supplied severity vector indicates potential low-impact confidentiality and integrity effects, with no availability impact.