CVE-2023-0232
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.32% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-02-21 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| hasthemes | shoplentor |
References
- https://plugins.trac.wordpress.org/changeset/2852711/woolentor-addons/trunk/includes/helper-function.php
- https://wpscan.com/vulnerability/1885a708-0e8a-4f4c-8e26-069bebe9a518
- https://plugins.trac.wordpress.org/changeset/2852711/woolentor-addons/trunk/includes/helper-function.php
- https://wpscan.com/vulnerability/1885a708-0e8a-4f4c-8e26-069bebe9a518
→ the Explorer · watch your stack · NVD