CVE-2024-8922
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 502
Summary
CVE-2024-8922 is a vulnerability affecting the Product Enquiry plugin for WooCommerce and WordPress. This issue allows authenticated attackers with Author-level access or higher to inject PHP objects via deserialization of untrusted input in the enquiry_detail.php file. No Pop chain has been identified in the vulnerable software, but if one exists through an additional plugin or theme, it could result in serious consequences, including file deletion, data theft, or code execution. All versions up to 2.2.33.32 are susceptible to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.