CVE-2024-56068
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 31, 2024
CWE ID 502
Summary
CVE-2024-56068 is a deserialization vulnerability affecting WP SuperBackup, a plugin used for creating backups in WordPress websites. The issue allows an attacker to execute arbitrary code by deserializing untrusted data. This vulnerability can be exploited if a user unknowingly restores a maliciously crafted backup file. WP SuperBackup versions from n/a through 2.3.3 are believed to be impacted by this issue. It is strongly recommended that users update their WP SuperBackup plugin to the latest version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.