The WP Meta SEO WordPress plugin before 4.5.5 does not...
High severity
Unreviewed
Published
Apr 10, 2023
to the GitHub Advisory Database
•
Updated Feb 11, 2025
Description
Published by the National Vulnerability Database
Apr 10, 2023
Published to the GitHub Advisory Database
Apr 10, 2023
Last updated
Feb 11, 2025
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.
References