The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
2023-01-02T22:15:16.933
2025-04-10T19:15:52.590
Modified
CVSSv3.1: 7.2 (HIGH)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | videousermanuals | white_label_cms | < 2.5 | Yes |