SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2023-3360

LOW · CVSS 3.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Weaver Show Posts WordPress plugin versions prior to 1.8.1 are vulnerable to PHP object injection due to improper unserialization of imported files. This issue allows high-privilege users to exploit the vulnerability by importing malicious files, potentially compromising the site's integrity if a suitable gadget chain exists. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2023-3360
Severity
LOW
CVSS
3.3
EPSS
0.15%
WordPress

Original NVD Description

The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.