wp-includes/functions.php in WordPress before 3.6.1 does...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Sep 12, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 11, 2025
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
References