CVE-2024-12562
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-12562 is a vulnerability affecting the s2Member Pro plugin for WordPress. The issue lies in the 's2member_pro_remote_op' parameter, which is susceptible to PHP Object Injection through deserialization of untrusted input. This vulnerability enables unauthenticated attackers to inject a PHP Object, potentially leading to file deletion, data theft, or code execution. However, no known POP (Return-Oriented Programming) chain exists within the s2Member Pro software itself. If such a chain is present in other plugins or themes installed on the target system, the attacker could further exploit the vulnerability to elevate their privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.