CVE-2023-28667 is a critical unauthenticated insecure deserialization vulnerability affecting the Lead Generated WordPress Plugin, versions 1.23 and earlier. This flaw allows an attacker to inject arbitrary PHP objects due to unsanitized input in the tve_labels parameter, potentially leading to full compromise of the affected system. With a CVSS score of 9.8, it presents a high-impact, low-complexity attack vector requiring no authentication. Despite its severity, there is currently no public exploit code, active exploitation, or significant community discussion reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25CPE matchmatch criteria | cpe:2.3:a:leadgenerated:lead_generated:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Insecure Deserialization in Multiple WordPress Plugins
Feb 22, 2023Insecure Deserialization in Multiple WordPress Plugins
Feb 22, 2023Insecure Deserialization in Multiple WordPress Plugins
Feb 22, 2023Insecure Deserialization in Multiple WordPress Plugins
Feb 22, 2023