CVE-2024-10828

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 502

Summary

CVE-2024-10828 is a critical vulnerability affecting the Advanced Order Export plugin for WordPress, versions up to 3.5.5. This issue allows unauthenticated attackers to perform PHP Object Injection via deserialization of untrusted input during Order export. With the presence of a POP chain, attackers can execute arbitrary file deletions, potentially leading to remote code execution. The vulnerable functionality is enabled by the "Try to convert serialized values" option.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share