PHP Object Injection Vulnerability in Puzzles WordPress Theme by ThemeForest
CVE-2024-13770
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 February 2025
What is CVE-2024-13770?
The Puzzles WordPress Magazine/Review Theme is susceptible to a PHP Object Injection vulnerability through the deserialization of untrusted input in the 'view_more_posts' AJAX action. This flaw affects all versions up to and including 4.2.4, allowing unauthenticated attackers to manipulate PHP objects. However, it is important to note that the impact of this vulnerability relies on the presence of a PHP Object Payload (POP) chain within other installed plugins or themes. Without such a chain, the vulnerability poses a minimal risk. The developer has removed the software from the repository and recommends users find an alternative.
Affected Version(s)
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4