CVE · High

CVE-2023-1347 — Customizer Export/Import [customizer-export-import] < 0.9.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1347 Customizer Export/Import [customizer-export-import] < 0.9.6 Deserialization of Untrusted Data High 7.2 < 0.9.6 0.9.6 2023-04-25

CVE-2023-1347

The Customizer Export/Import plugin through version 0.9.5 contains a PHP Object Injection vulnerability stemming from unsafe deserialization of data imported from files. Attackers with administrator privileges can inject malicious PHP objects during the import process. While the plugin itself lacks a gadget chain for exploitation, the presence of one in other installed plugins or themes could enable attackers to execute arbitrary code, extract confidential information, or remove files from the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.