SB2022120112 - PHP code execution in WordPress Smart Slider 3 plugin
Published: December 1, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Code Injection (CVE-ID: CVE-2022-45845)
The vulnerability allows a remote user to inject and execute arbitrary PHP code.
The vulnerability exists due to improper input validation. A remote user can send a specially crafted HTTP request and execute arbitrary PHP code on the server.
Remediation
Install update from vendor's website.