Description
WordPress Plugin Otter-Gutenberg Blocks-Page Builder for Gutenberg Editor & FSE is prone to a deserialization vulnerability. Attackers can possibly exploit this issue to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions, granted a POP chain is also present. WordPress Plugin Otter-Gutenberg Blocks-Page Builder for Gutenberg Editor & FSE version 2.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.6 or latest
References
Related Vulnerabilities
Oracle JRE CVE-2013-2471 Vulnerability (CVE-2013-2471)
WordPress Plugin IMPress for IDX Broker Multiple Vulnerabilities (2.6.1)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3454)
phpMyAdmin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000013)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2022-23307)