CVE-2024-11465
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-11465 is a vulnerability affecting the Custom Product Tabs plugin for WooCommerce on WordPress. The issue lies in the 'yikes_woo_products_tabs' post meta parameter, which is susceptible to PHP Object Injection through deserialization of untrusted input. This vulnerability enables authenticated attackers with Shop Manager-level access or higher to inject a PHP Object. No Pop chain has been identified in the vulnerable software, but if present via an additional plugin or theme, it could potentially allow the attacker to delete files, retrieve sensitive information, or execute code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- YIKES Inc.