PT-2026-102356 · WordPress · Convertplus
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ConvertPlus versions prior to 3.6.4
Description
The plugin is susceptible to deserialization of untrusted data through the
style parameter of the cp display preview modal AJAX action. The issue occurs because the nonce guard is bypassed when the cp admin page nonce parameter is omitted, and no capability check is performed on the callback. Additionally, the sanitize text field() function fails to strip shortcode delimiters from the $style value before it is processed by do shortcode(). This allows authenticated attackers with Subscriber-level access or higher to inject a [smile modal] invocation, leading the smile modal popup() function to pass base64-decoded bytes to maybe unserialize() without allowed classes restrictions. This enables the injection of PHP objects. While no POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is present in the software itself, the presence of a POP chain in another installed plugin or theme could allow attackers to delete arbitrary files, retrieve sensitive data, or execute code.Recommendations
Update the plugin to a version newer than 3.6.3.
As a temporary mitigation, restrict access to the
cp display preview modal AJAX action or avoid using the style parameter until the update is applied.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Convertplus