CVE-2024-12721

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Dec 21, 2024
Updated: Mar 1, 2025
CWE ID 502

Summary

CVE-2024-12721 is a vulnerability affecting the Custom Product Tabs For WooCommerce plugin for WordPress. The issue involves PHP Object Injection, which can be exploited through deserialization of untrusted input from the 'wb_custom_tabs' parameter. This vulnerability enables authenticated attackers with Shop Manager-level access or higher to inject a PHP Object. No Pop chain has been identified in this software, but the presence of one via an additional plugin or theme could potentially allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share