VYPR
High severity8.8NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026

CVE-2023-2288

CVE-2023-2288

Description

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:themeisle:otter:*:*:*:*:*:wordpress:*:*
    Range: <2.2.6
  • WordPress/Otterdescription
  • WordPress/Otterllm-create
    Range: <2.2.6

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.