CVE-2024-13770

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 13, 2025
Updated: Feb 24, 2025
CWE ID 502

Summary

CVE-2024-13770: The Puzzles WP Magazine/Review theme for WordPress, versions up to 4.2.4, is susceptible to PHP Object Injection via deserialization of untrusted input 'view_more_posts' in the AJAX action. This vulnerability allows unauthenticated attackers to inject PHP Objects, but does not enable any further exploitation on its own. However, if a POP (Return-Oriented Programming) chain is present in an additional plugin or theme installed on the target system, attackers may exploit this vulnerability to delete files, retrieve sensitive data, or execute code. The developer has removed the software from the repository, leaving users without an update and in need of a replacement solution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share