Unrated severityNVD Advisory· Published Sep 12, 2013· Updated Apr 29, 2026
CVE-2013-4338
CVE-2013-4338
Description
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
Affected products
1- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*Range: <=3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- wordpress.org/news/2013/09/wordpress-3-6-1/nvdPatchVendor Advisory
- core.trac.wordpress.org/changeset/25325nvdExploitPatch
- codex.wordpress.org/Version_3.6.1nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2013-September/116828.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-September/116832.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-September/117118.htmlnvd
- www.debian.org/security/2013/dsa-2757nvd
News mentions
0No linked articles in our index yet.