CVE Vulnerabilities

CVE-2023-0232

Published: Feb 21, 2023 | Modified: Mar 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

Affected Software

NameVendorStart VersionEnd Version
ShoplentorHasthemes*2.5.4 (excluding)

References