WordPress Mail Picker plugin <= 1.0.14 - PHP Object Injection vulnerability
CVE-2024-54273

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 December 2024

What is CVE-2024-54273?

The vulnerability in PickPlugins Mail Picker arises from a deserialization of untrusted data, leading to potential object injection attacks. This flaw impacts versions of Mail Picker up to 1.0.14 and allows attackers to manipulate serialized objects that can lead to the execution of arbitrary code within the application context. Users of Mail Picker should take immediate steps to assess their installations and apply necessary security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Mail Picker <= 1.0.14

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.