Deserialization of Untrusted Data Vulnerability Affects MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce - WpEvently - WordPress Plugin
CVE-2024-24796
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 12 February 2024
Summary
The MagePeople Event Manager and Tickets Selling Plugin for WooCommerce is susceptible to a deserialization of untrusted data vulnerability. This flaw allows attackers to potentially execute arbitrary PHP code, leading to severe security implications. Specifically, it affects versions from the initial release through 4.1.1, threatening the integrity and confidentiality of the WordPress sites that utilize this plugin. Site administrators are urged to review the plugin's configurations and verify they are not running an affected version to safeguard against potential exploitation.
Affected Version(s)
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin <= 4.1.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
NGÔ THIÊN AN / ancorn_ from VNPT-VCI (Patchstack Alliance)