CVE-2024-56068

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 31, 2024
CWE ID 502

Summary

CVE-2024-56068 is a deserialization vulnerability affecting WP SuperBackup, a plugin used for creating backups in WordPress websites. The issue allows an attacker to execute arbitrary code by deserializing untrusted data. This vulnerability can be exploited if a user unknowingly restores a maliciously crafted backup file. WP SuperBackup versions from n/a through 2.3.3 are believed to be impacted by this issue. It is strongly recommended that users update their WP SuperBackup plugin to the latest version to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share