CVE-2024-8922

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 502

Summary

CVE-2024-8922 is a vulnerability affecting the Product Enquiry plugin for WooCommerce and WordPress. This issue allows authenticated attackers with Author-level access or higher to inject PHP objects via deserialization of untrusted input in the enquiry_detail.php file. No Pop chain has been identified in the vulnerable software, but if one exists through an additional plugin or theme, it could result in serious consequences, including file deletion, data theft, or code execution. All versions up to 2.2.33.32 are susceptible to this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share