The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://dumpco.re/bugs/wp-plugin-virim-id | third party advisory exploit |
https://wpvulndb.com/vulnerabilities/9291 |