The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://wordpress.org/plugins/option-tree/#developers | release notes |
https://wpvulndb.com/vulnerabilities/9600 | third party advisory |