Deserialization of Untrusted Data Vulnerability Affects CodeSolz Better Find and Replace
CVE-2024-39636

8.3HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
1 August 2024

Summary

A deserialization of untrusted data vulnerability exists in the Better Find and Replace plugin by CodeSolz. This vulnerability allows an attacker to exploit flaws in the way the application processes serialized objects, potentially leading to arbitrary code execution or other malicious outcomes. The affected versions of Better Find and Replace range from unspecified releases up to 1.6.1, making it crucial for users to apply updates or patches to mitigate risks associated with this issue.

Affected Version(s)

Better Find and Replace <= 1.6.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Trình Vũ / Sonicrrrr_ from VNPT-VCI (Patchstack Alliance)
.