CVE-2023-47507: WordPress Master Slider Pro Plugin <= 3.6.5 is vulnerable to PHP Object Injection
Published Dec 20, 2023
·Updated
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.
Affected Software
1 affected component
averta Master Slider Pro Wordpress<=3.6.5
Event History
Dec 20, 2023
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47507?
CVE-2023-47507 has a medium severity rating due to the potential for remote code execution through deserialization of untrusted data.
2
How do I fix CVE-2023-47507?
To fix CVE-2023-47507, update the Master Slider Pro plugin to version 3.6.6 or later.
3
What systems are affected by CVE-2023-47507?
CVE-2023-47507 affects Master Slider Pro versions from n/a through 3.6.5.
4
Can CVE-2023-47507 lead to a data breach?
Yes, CVE-2023-47507 can potentially lead to unauthorized access and a data breach due to the nature of deserialized untrusted data.
5
Is there a workaround for CVE-2023-47507?
While updating is the best solution, disabling the Master Slider Pro plugin temporarily can serve as a workaround until the update is applied.