Vulnerabilities > CVE-2017-18604 - Deserialization of Untrusted Data vulnerability in Sitebuilder Dynamic Components Project Sitebuilder Dynamic Components 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE

Summary

The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.

Common Weakness Enumeration (CWE)