CVE-2023-6528
The Slider Revolution plugin for WordPress contains a PHP Object Injection vulnerability affecting versions below 6.6.19 that occurs during slider import operations through unsafe deserialization of user-supplied data. Authenticated users with author privileges or higher can inject malicious PHP objects, though the plugin itself lacks an exploitable POP chain. However, if other installed plugins or themes provide a viable POP chain, attackers could potentially execute arbitrary code, exfiltrate sensitive information, or remove files from the system.
Based on public CVE data (MITRE/NVD).