CRITICAL

CVE-2023-26326

CVSS v3

9.8

CRITICAL

EPSS Score

41.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

Technical details

Published
2/23/2023

Frequently asked questions

What is CVE-2023-26326?

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

Is CVE-2023-26326 actively exploited?

Active exploitation of CVE-2023-26326 has not been confirmed. The EPSS score is 41.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26326?

CVE-2023-26326 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-26326 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.