CVE-2024-12313
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Jan 7, 2025
CWE ID 502
Summary
CVE-2024-12313 is a vulnerability affecting the Compare Products for WooCommerce plugin for WordPress. This issue allows unauthenticated attackers to inject PHP Objects through deserialization of untrusted input in the 'woo_compare_list' cookie. The vulnerability does not require a pop chain to exploit, but if one exists via an additional plugin or theme, an attacker could delete files, retrieve sensitive data, or execute arbitrary code. All versions of the plugin up to and including 3.2.1 are impacted.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.