CVE-2024-13921
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-13921 is a vulnerability affecting the Order Export & Order Import plugin for WooCommerce on WordPress. The issue lies in the deserialization of untrusted input from the 'form_data' parameter, which allows authenticated attackers with Administrator-level access to inject a PHP Object. No known Pop Chain is present in the vulnerable software, so this vulnerability doesn't pose a threat on its own. However, if a Pop Chain is present through another plugin or theme on the target system, the attacker could potentially delete files, retrieve sensitive data, or execute code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.