CVE-2024-10957
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-10957 is a vulnerability affecting the UpdraftPlus: WP Backup & Migration Plugin used in WordPress. The flaw, present in versions 1.23.8 to 1.24.11, allows unauthenticated attackers to inject PHP Objects through deserialization of untrusted input in the 'recursive_unserialized_replace' function. No Pop Pop chain is present in the vulnerable software, so the impact is limited until another plugin or theme with a Pop chain is installed. A successful exploit could result in file deletion, data retrieval, or code execution, depending on the Pop chain present. An administrator can trigger the vulnerability by performing a search and replace action.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- UpdraftPlus
Affected Vendors
- Updraftplus