Security Advisory

CVE-2021-24857

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-13 10:41:09
Last updated 2024-08-03 19:42:17
Assigner WPScan
State PUBLISHED

Description

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.