The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://wordpress.org/plugins/option-tree/#developers | release notes |
https://wpvulndb.com/vulnerabilities/9599 | third party advisory |