Unauthenticated PHP Object Injection Vulnerability in Print Science Designer Plugin
CVE-2024-12312
What is CVE-2024-12312?
The Print Science Designer plugin for WordPress is affected by a PHP Object Injection vulnerability across all versions up to and including 1.3.152. This vulnerability arises from the deserialization of untrusted input through the 'designer-saved-projects' cookie, allowing unauthenticated attackers to exploit the flaw. Although no known PHP Object Pattern (POP) chain exists within the vulnerable software, the presence of an additional plugin or theme that facilitates such a chain could grant attackers the ability to delete arbitrary files, access sensitive information, or execute malicious code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Print Science Designer * <= 1.3.152
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved