PHP Object Injection Vulnerability in Puzzles WordPress Theme by ThemeForest
CVE-2024-13770

9.8CRITICAL

What is CVE-2024-13770?

The Puzzles WordPress Magazine/Review Theme is susceptible to a PHP Object Injection vulnerability through the deserialization of untrusted input in the 'view_more_posts' AJAX action. This flaw affects all versions up to and including 4.2.4, allowing unauthenticated attackers to manipulate PHP objects. However, it is important to note that the impact of this vulnerability relies on the presence of a PHP Object Payload (POP) chain within other installed plugins or themes. Without such a chain, the vulnerability poses a minimal risk. The developer has removed the software from the repository and recommends users find an alternative.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.