Update the WordPress Customizer Export/Import plugin to the latest available version (at least 0.9.5).
Nguyen Duy Quoc Khanh discovered and reported this PHP Object Injection vulnerability in WordPress Customizer Export/Import Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 0.9.5.
Have additional information or questions about this entry? Get in touch.