CVE-2024-9664

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 7, 2025
Updated: Feb 11, 2025
CWE ID 502

Summary

CVE-2024-9664 is a vulnerability affecting the WP All Import Pro plugin for WordPress. This issue permits authenticated attackers with Administrator-level access to inject PHP Objects through deserialization of untrusted input from import files. No Pop chain is present in the plugin itself, but the presence of one via an additional plugin or theme could lead to deletion of arbitrary files, data extraction, or code execution. All versions up to 4.9.7 are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share