Untrusted Data Deserialization Vulnerability Affects SiteBuilder Dynamic Components
CVE-2024-49625
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 20 October 2024
Summary
A deserialization of untrusted data vulnerability exists in SiteBuilder Dynamic Components by Brandon Clark. This issue allows for object injection, enabling attackers to manipulate the application's behavior or access sensitive data. The affected versions span from any version up to 1.0. Organizations utilizing this product should prioritize remediation to protect against potential exploitation.
Affected Version(s)
SiteBuilder Dynamic Components <= 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)