CyberRota Analysis
AI-GeneratedThe Weaver Show Posts WordPress plugin versions prior to 1.8.1 are vulnerable to PHP object injection due to improper unserialization of imported files. This issue allows high-privilege users to exploit the vulnerability by importing malicious files, potentially compromising the site's integrity if a suitable gadget chain exists. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.