MyCred Deserialization of Untrusted Data Vulnerability Leads to Object Injection
CVE-2024-43354
9.8CRITICAL
What is CVE-2024-43354?
A deserialization of untrusted data vulnerability in the myCred WordPress plugin allows for object injection, which could allow an attacker to execute arbitrary code. This issue impacts versions of myCred from n/a to 2.7.2, highlighting the importance of updating to secure the application from potential exploitation.
Affected Version(s)
myCred 0 <= 2.7.2