Vulnerabilities > CVE-2023-6528 - Deserialization of Untrusted Data vulnerability in Themepunch Slider Revolution

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
themepunch
CWE-502

Summary

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

Vulnerable Configurations

Part Description Count
Application
Themepunch
112

Common Weakness Enumeration (CWE)