Product
The Live Composer plugin for WordPress (<= 2.1.18) contains a PHP object injection vulnerability that allows authenticated contributors to achieve remote code execution if a compatible POP chain exists in the environment.