CVE-2020-36727

T

he Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.

Configurations

Configuration 1 (hide)

cpe:2.3:a:xyzscripts:newsletter_manager:*:*:-:*:-:wordpress:*:*

History

21 Nov 2024, 05:30

Type Values Removed Values Added
References () https://blog.nintechnet.com/insecure-deserialization-vulnerability-in-wordpress-newsletter-manager-plugin-unpatched/ - Exploit () https://blog.nintechnet.com/insecure-deserialization-vulnerability-in-wordpress-newsletter-manager-plugin-unpatched/ - Exploit
References () https://wpscan.com/vulnerability/b82124b1-e5e1-4f1e-9513-90474fd3f066 - Third Party Advisory () https://wpscan.com/vulnerability/b82124b1-e5e1-4f1e-9513-90474fd3f066 - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/dcfd8c4d-d48b-468d-a7d5-1ec05b068f79?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/dcfd8c4d-d48b-468d-a7d5-1ec05b068f79?source=cve - Third Party Advisory

Information

Published : 2023-06-07 02:15

Updated : 2024-11-21 05:30


NVD link : CVE-2020-36727

Mitre link : CVE-2020-36727

CVE.ORG link : CVE-2020-36727


JSON object : View

Products Affected
CWE
CWE-502

Deserialization of Untrusted Data