PHP Object Injection Vulnerability in Puzzles WordPress Theme by ThemeForest
CVE-2024-13770
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 February 2025
What is CVE-2024-13770?
The Puzzles WordPress Magazine/Review Theme is susceptible to a PHP Object Injection vulnerability through the deserialization of untrusted input in the 'view_more_posts' AJAX action. This flaw affects all versions up to and including 4.2.4, allowing unauthenticated attackers to manipulate PHP objects. However, it is important to note that the impact of this vulnerability relies on the presence of a PHP Object Payload (POP) chain within other installed plugins or themes. Without such a chain, the vulnerability poses a minimal risk. The developer has removed the software from the repository and recommends users find an alternative.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved