Thursday, January 26, 2017

Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability


The Google Forms WordPress Plugin fetches a published Google Form using a WordPress custom post or shortcode, removes the Google wrapper HTML and then renders it as an HTML form embedded in your blog post or page.

A PHP Object injection vulnerability was found in the Google Forms WordPress Plugin, which can be used by an unauthenticated user to instantiate arbitrary PHP Objects.

Read More at GBHackers On Security

No comments:

Post a Comment