Deserialization of Untrusted Data Vulnerability Affects MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce - WpEvently - WordPress Plugin
CVE-2024-24796
8.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 February 2024
What is CVE-2024-24796?
The MagePeople Event Manager and Tickets Selling Plugin for WooCommerce is susceptible to a deserialization of untrusted data vulnerability. This flaw allows attackers to potentially execute arbitrary PHP code, leading to severe security implications. Specifically, it affects versions from the initial release through 4.1.1, threatening the integrity and confidentiality of the WordPress sites that utilize this plugin. Site administrators are urged to review the plugin's configurations and verify they are not running an affected version to safeguard against potential exploitation.
Affected Version(s)
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin <= 4.1.1
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
NGÔ THIÊN AN / ancorn_ from VNPT-VCI (Patchstack Alliance)