WP Engine WP Migrate Plugin Unauthenticated PHP Object Injection Vulnerability
Vulnerability
A deserialization vulnerability allowing PHP object injection has been identified in the WP Engine WP Migrate plugin, affecting versions through 2.6.10. This vulnerability could be exploited to execute arbitrary code, inject SQL, traverse directories, cause a denial of service, and more, if a suitable object injection chain is available.
Impact
Exploitation of this vulnerability could lead to unauthorized PHP object injection, with the potential for executing arbitrary code, injecting malicious SQL, traversing directories in an unauthorized manner, causing a denial of service, and other impacts, depending on the exploitation chain used.
Remediation
Users of the WP Migrate plugin should update to version 2.6.11 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
