The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://dumpco.re/bugs/wp-plugin-carts-guru-id | third party advisory exploit |
https://wpvulndb.com/vulnerabilities/9292 |