CVE-2024-7432

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 1, 2024
Updated: Nov 13, 2024
CWE ID 502

Summary

CVE-2024-7432 is a vulnerability affecting the Unseen Blog theme for WordPress. This issue, present in all versions up to 1.0.0, permits authenticated attackers with Contributor-level access or higher to inject PHP Objects through deserialization of untrusted input. No Pop chain is known to be present in the vulnerable software, but the presence of such a chain via an additional plugin or theme could potentially allow the attacker to execute arbitrary code, delete files, or access sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share