Description
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
Remediation
References
Related Vulnerabilities
WordPress Plugin Process Steps Template Designer Cross-Site Request Forgery (1.2.1)
Apache Tomcat version older than 6.0.18
WordPress Plugin PayPal for WooCommerce Security Bypass (1.5.7)
Apache Tomcat Other Vulnerability (CVE-2000-0759)
WordPress Plugin Verve Meta Boxes TimThumb Arbitrary File Upload (1.2.8)