CMB2 Plugin Vulnerable to PHP Object Injection
CVE-2024-1792

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 April 2024

What is CVE-2024-1792?

The CMB2 plugin for WordPress, utilized primarily as a developer toolkit, is susceptible to PHP Object Injection due to the deserialization of untrusted input in the text_datetime_timestamp_timezone field. This vulnerability affects all versions up to and including 2.10.1. Authenticated attackers with contributor access or higher can exploit this flaw to inject a PHP Object. While a direct proof of concept (POP) chain is not inherent within the plugin itself, the risk escalates if other plugins or themes create such a chain in conjunction with CMB2. If an appropriate metabox activation is implemented (for example, through functions.php), the potential for an attacker to delete files, access sensitive data, or execute arbitrary code significantly increases.

Affected Version(s)

CMB2 0 <= 2.10.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.