Deserialization of Untrusted Data Vulnerability Affects Participants Database
CVE-2024-43141

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 August 2024

Summary

An identified vulnerability pertaining to the Participants Database plugin, developed by Roland Barker, exposes systems to the risk of object injection due to the deserialization of untrusted data. This vulnerability impacts versions from an unspecified release through 2.5.9.2, enabling potential attackers to exploit the affected system. Proper mitigation measures should be considered to safeguard against this flaw, as it may allow the execution of arbitrary PHP code leading to unauthorized access and manipulation of the database.

Affected Version(s)

Participants Database <= 2.5.9.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.