Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain
CVE-2021-24217

8.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
12 April 2021

Summary

The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

Affected Version(s)

Facebook for WordPress 3.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
.