Description b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. Remediation References CVE-2016-8901 Related Vulnerabilities WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-24306) WordPress Plugin WP Mobile Detector Multiple Vulnerabilities (3.8) WordPress 5.8.x Multiple Vulnerabilities (5.8 - 5.8.8) WordPress Plugin Profiles 'bio-img.php' SQL Injection (2.0RC1) Oracle Database Server Improper Input Validation Vulnerability (CVE-2016-2381) Severity Critical Classification CVE-2016-8901 CWE-138 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities