CVE-2020-36727

CVE-2020-36727

The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the ‘customFieldsDetails’ parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.

Source: CVE-2020-36727

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다