Vulnerability in Timeline Event History plugin for WordPress can lead to PHP Object Injection
CVE-2024-5726
What is CVE-2024-5726?
The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection due to improper handling of unsanitized input from the 'timelines-data' parameter. This weakness affects all versions up to and including version 3.1. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to introduce a malicious PHP Object. Although no proven Payload Object Property (POP) chain exists within the vulnerable software, the presence of additional plugins or themes could enable attackers to leverage this vulnerability for malicious purposes, such as deleting arbitrary files, accessing sensitive information, or executing unauthorized code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Timeline Event History * <= 3.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved