Deserialization of Untrusted Data Vulnerability Affects BetterDocs
CVE-2024-30226

9CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 March 2024

Summary

A deserialization of untrusted data vulnerability exists in the BetterDocs plugin for WordPress, which allows attackers to exploit the deserialization process. This issue affects all versions of BetterDocs up to and including 3.3.3. An attacker could potentially execute arbitrary PHP code and gain control over the affected WordPress instance. It is crucial for users of BetterDocs to apply the necessary patches and updates to secure their applications and protect against potential exploits.

Affected Version(s)

BetterDocs <= 3.3.3

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.