The Anti-Malware Security and Brute-Force Firewall...
High severity
Unreviewed
Published
Jan 16, 2023
to the GitHub Advisory Database
•
Updated Jan 24, 2023
Description
Published by the National Vulnerability Database
Jan 16, 2023
Published to the GitHub Advisory Database
Jan 16, 2023
Last updated
Jan 24, 2023
The Anti-Malware Security and Brute-Force Firewall WordPress plugin through 4.21.85 is prone to a PHP Object Injection vulnerability due to the unsafe use of unserialize() function. A potential attacker, authenticated as high privilege user could exploit this vulnerability by sending specially crafted requests to the web application containing malicious serialized input.
References