peter bassill · operator
$ cve CVE-2023-26326 JSON

CVE-2023-26326

9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.82% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2023-02-23
Last modified2026-06-17

Affected (1)

VendorProduct
themekraftbuddyforms

References

→ the Explorer  ·  watch your stack  ·  NVD