Stop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 18%
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Stop Spammers Security | Block Spam Users, Comments, Formspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/e8bb79db-ef77-43be-b449-4c4b5310eedfunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.