CVE-2024-13921

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 20, 2025
Updated: Mar 26, 2025
CWE ID 502

Summary

CVE-2024-13921 is a vulnerability affecting the Order Export & Order Import plugin for WooCommerce on WordPress. The issue lies in the deserialization of untrusted input from the 'form_data' parameter, which allows authenticated attackers with Administrator-level access to inject a PHP Object. No known Pop Chain is present in the vulnerable software, so this vulnerability doesn't pose a threat on its own. However, if a Pop Chain is present through another plugin or theme on the target system, the attacker could potentially delete files, retrieve sensitive data, or execute code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share