CMB2 Plugin Vulnerable to PHP Object Injection
CVE-2024-1792
What is CVE-2024-1792?
The CMB2 plugin for WordPress, utilized primarily as a developer toolkit, is susceptible to PHP Object Injection due to the deserialization of untrusted input in the text_datetime_timestamp_timezone field. This vulnerability affects all versions up to and including 2.10.1. Authenticated attackers with contributor access or higher can exploit this flaw to inject a PHP Object. While a direct proof of concept (POP) chain is not inherent within the plugin itself, the risk escalates if other plugins or themes create such a chain in conjunction with CMB2. If an appropriate metabox activation is implemented (for example, through functions.php), the potential for an attacker to delete files, access sensitive data, or execute arbitrary code significantly increases.
Affected Version(s)
CMB2 0 <= 2.10.1