CVE-2023-4971
Last modified
CVE-2023-4971 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Weavertheme | Weaver Xtreme Theme Support | < 6.3.1 |
References
- https://wpscan.com/vulnerability/421194e1-6c3f-4972-8f3c-de1b9d2bcb13Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/421194e1-6c3f-4972-8f3c-de1b9d2bcb13Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4971?
How severe is CVE-2023-4971?
How do I fix CVE-2023-4971?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4970The PubyDoc WordPress plugin through 2.0.6 does not sanitise…4.8
- CVE-2023-49700Security best practices violations, a string operation in St…7.5
- CVE-2023-49701Memory Corruption in SIM management while USIMPhase2init 9.8
- CVE-2023-49706Defective request context handling in Self Service in LinOTP…6.8
- CVE-2023-49707SQLi vulnerability in S5 Register module for Joomla.9.8
- CVE-2023-49708SQLi vulnerability in Starshop component for Joomla.9.8
- CVE-2023-49710Rejected reason: This is unused.
- CVE-2023-49712Rejected reason: This is unused.
- CVE-2023-49713Denial-of-service (DoS) vulnerability exists in NetBIOS serv…7.5
- CVE-2023-49715A unrestricted php file upload vulnerability exists in the i…8.8
- CVE-2023-49716 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA product…9.8
- CVE-2023-4972Incorrect Use of Privileged APIs vulnerability in Yepas Digi…9.8
Are you affected by CVE-2023-4971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
