CVE-2024-13789
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-13789 is a vulnerability affecting the ravpage plugin for WordPress. This issue allows unauthenticated attackers to inject a PHP Object through deserialization of untrusted input from the 'paramsv2' parameter. However, the impact of this vulnerability is limited, as it does not have an impact unless another plugin or theme with a POP (Return-Oriented Programming) chain is installed on the site. If a POP chain is present, the attacker may be able to delete files, retrieve sensitive data, or execute code. It is important to note that the vulnerability lies in the ravpage plugin itself and not in WordPress core. WordPress users are encouraged to update to the latest version of the ravpage plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.