Smush – Optimize, Compress and Lazy Load Images, 1b7b9063d6297ef0cf4d01b221d4e4da2c885eb9
- CVE, Research URL
- Published on
- Dec 10, 2018
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.0.1 Smush – Lazy Load Images, Optimize & Compress Images <= 3.0.0 - Authenticated PHAR Deserialization The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 3.0.0. This makes it possible for authenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
- Affected versions
-
max 3.0.1.
- Status
-
vulnerable