CVE-2024-10957

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 4, 2025
Updated: Jan 6, 2025
CWE ID 502

Summary

CVE-2024-10957 is a vulnerability affecting the UpdraftPlus: WP Backup & Migration Plugin used in WordPress. The flaw, present in versions 1.23.8 to 1.24.11, allows unauthenticated attackers to inject PHP Objects through deserialization of untrusted input in the 'recursive_unserialized_replace' function. No Pop Pop chain is present in the vulnerable software, so the impact is limited until another plugin or theme with a Pop chain is installed. A successful exploit could result in file deletion, data retrieval, or code execution, depending on the Pop chain present. An administrator can trigger the vulnerability by performing a search and replace action.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share