WordPress Mail Picker plugin <= 1.0.14 - PHP Object Injection vulnerability
CVE-2024-54273
9.8CRITICAL
What is CVE-2024-54273?
The vulnerability in PickPlugins Mail Picker arises from a deserialization of untrusted data, leading to potential object injection attacks. This flaw impacts versions of Mail Picker up to 1.0.14 and allows attackers to manipulate serialized objects that can lead to the execution of arbitrary code within the application context. Users of Mail Picker should take immediate steps to assess their installations and apply necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
Mail Picker <= 1.0.14