9.8
CVSSv3

CVE-2020-36726

Published: 07/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated malicious users to inject a PHP Object. No POP chain is present in the vulnerable plugin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

etoilewebdesign ultimate reviews