CVE-2023-3360
Received Received - Intake

Weaver Show Posts Plugin PHP Object Injection Vulnerability

Vulnerability report for CVE-2023-3360, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
weaver show_posts to 1.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Weaver Show Posts WordPress plugin before version 1.8.1 has a vulnerability where it unserializes data from imported files without proper validation. This can lead to PHP object injection if an attacker with high privileges uploads a malicious file containing a crafted serialized PHP object. If a suitable gadget chain exists on the system, this could allow arbitrary code execution.

Detection Guidance

Check the installed version of the Weaver Show Posts WordPress plugin. If it is below 1.8.1, the system is vulnerable. Look for suspicious file uploads or deserialization activity in logs.

Impact Analysis

An authenticated administrator-level attacker could exploit this to execute arbitrary code on your WordPress site by uploading a malicious file. This could lead to full system compromise, data theft, or further attacks on your server. The impact depends on the privileges of the compromised account and the presence of gadget chains.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or code execution, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations could face fines or penalties if user data is compromised due to this flaw.

Mitigation Strategies

Update the Weaver Show Posts plugin to version 1.8.1 or later immediately. Remove any unauthorized or suspicious files uploaded to the system. Review user roles to ensure only trusted administrators have upload permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-3360. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart