PT-2026-73103 · Weavertheme · Turnkey Bbpress
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Turnkey bbPress by WeaverTheme versions prior to 1.7.2
Description
The plugin is susceptible to PHP Object Injection, a condition where untrusted data is passed to the
unserialize() function, potentially allowing an attacker to manipulate application logic. The issue occurs within the wvrbbp set to serialized values() function, which is accessed via the wvrbbp save restore() settings-restore handler. The function processes the raw contents of a file uploaded by an administrator without proper validation. Authenticated attackers with administrator-level access or higher can exploit this to inject a PHP Object. While no POP chain (a sequence of gadgets used to achieve code execution) exists within the plugin itself, the presence of one in another installed plugin or theme could enable the deletion of arbitrary files, retrieval of sensitive data, or remote code execution.Recommendations
Update the plugin to a version newer than 1.7.1.
As a temporary mitigation, restrict the use of the
wvrbbp save restore() settings-restore handler.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Turnkey Bbpress