Untrusted Data Deserialization Vulnerability Affects SiteBuilder Dynamic Components
CVE-2024-49625

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 October 2024

Summary

A deserialization of untrusted data vulnerability exists in SiteBuilder Dynamic Components by Brandon Clark. This issue allows for object injection, enabling attackers to manipulate the application's behavior or access sensitive data. The affected versions span from any version up to 1.0. Organizations utilizing this product should prioritize remediation to protect against potential exploitation.

Affected Version(s)

SiteBuilder Dynamic Components <= 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.