PHP object injection

GiveWP Vulnerability– Donation Plugin and Fundraising Platform – Multiple Vulnerabilities – CVE-2024-5939, CVE-2024-5940, CVE-2024-5941, CVE-2024-5932 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 19, 2024

Plugin Name: GiveWP – Donation Plugin and Fundraising Platform Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 7,784,276 Active Installs: 100,000 Last Updated: August 19, 2024 Patched Versions: 3.14.0, 3.14.2 Affected Versions: <= 3.13.0, <= 3.14.1 Vulnerability 1 Details: Name: GiveWP – Donation Plugin and Fundraising Platform…

Read More

Contact Form Plugin Vulnerability – PHP Object Injection via extractDynamicValues – CVE-2024-4157 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 21, 2024

Plugin Name: Contact Form Plugin Key Information: Software Type: Plugin Software Slug: fluentform Software Status: Active Software Author: techjewel Software Downloads: 7,048,138 Active Installs: 400,000 Last Updated: May 21, 2024 Patched Versions: 5.1.16 Affected Versions: <= 5.1.15 Vulnerability Details: Name: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form…

Read More

Order Export & Order Import for WooCommerce Vulnerability – Authenticated (Administrator+) PHP Object Injection – CVE-2024-34751 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 14, 2024

Plugin Name: Order Export & Order Import for WooCommerce Key Information: Software Type: Plugin Software Slug: order-import-export-for-woocommerce Software Status: Active Software Author: webtoffee Software Downloads: 1,536,946 Active Installs: 50,000 Last Updated: May 14, 2024 Patched Versions: 2.5.0 Affected Versions: <= 2.4.9 Vulnerability Details: Name: Order Export & Order Import for WooCommerce <= 2.4.9 – Authenticated…

Read More

One Click Demo Import Vulnerability – Authenticated (Admin+) PHP Object Injection – CVE-2024-34433 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 7, 2024

Plugin Name: One Click Demo Import Key Information: Software Type: Plugin Software Slug: one-click-demo-import Software Status: Active Software Author: smub Software Downloads: 15,730,116 Active Installs: 1,000,000 Last Updated: May 7, 2024 Patched Versions: 3.2.1 Affected Versions: <= 3.2.0 Vulnerability Details: Name: One Click Demo Import <= 3.2.0 – Authenticated (Admin+) PHP Object Injection Type: Deserialization…

Read More

GiveWP Vulnerability – Donation Plugin and Fundraising Platform – Authenticated PHP Object Injection – CVE-2024-30229 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Apr 26, 2024

Plugin Name: GiveWP – Donation Plugin and Fundraising Platform Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 7,225,697 Active Installs: 100,000 Last Updated: May 13, 2024 Patched Versions: 3.5.0 Affected Versions: <= 3.4.2 Vulnerability Details: Name: GiveWP – Donation Plugin and Fundraising Platform <= 3.4.2 Title: Authenticated…

Read More

Carousel, Slider, Gallery by WP Carousel Vulnerability Vulnerability – Authenticated (Admin+) PHP Object Injection – CVE-2024-3020 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 9, 2024

Plugin Name: Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce Key Information: Software Type: Plugin Software Slug: wp-carousel-free Software Status: Active Software Author: shapedplugin Software Downloads: 1,322,070 Active Installs: 60,000 Last Updated: April 16, 2024 Patched Versions: 2.6.4 Affected…

Read More

CMB2 Vulnerability – Authenticated PHP Object Injection – CVE-2024-1792 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 3, 2024

Plugin Name: CMB2 Key Information: Software Type: Plugin Software Slug: cmb2 Software Status: Active Software Author: jtsternberg Software Downloads: 4,198,199 Active Installs: 300,000 Last Updated: April 3, 2024 Patched Versions: 2.11.0 Affected Versions: <= 2.10.1 Vulnerability Details: Name: CMB2 <= 2.10.1 Title: Authenticated PHP Object Injection Type: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-1792 CVSS Score: 7.2 Publicly Published:…

Read More

Essential Addons for Elementor Vulnerability – Best Elementor Templates, Widgets, Kits & WooCommerce Builders – Authenticated (Author+) PHP Object Injection via error_resetpassword – CVE-2024-3018 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 29, 2024

Plugin Name: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 69,249,566 Active Installs: 2,000,000 Last Updated: April 3, 2024 Patched Versions: 5.9.14 Affected Versions: <= 5.9.13 Vulnerability Details: Name: Essential Addons for Elementor <=…

Read More

Meta Tag Manager Vulnerability – Authenticated (Subscriber+) PHP Object Injection – CVE-2024-1770 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 27, 2024

Plugin Name: Meta Tag Manager Key Information: Software Type: Plugin Software Slug: meta-tag-manager Software Status: Active Software Author: netweblogic Software Downloads: 865,531 Active Installs: 100,000 Last Updated: March 27, 2024 Patched Versions: 3.1 Affected Versions: <= 3.0.2 Vulnerability Details: Name: Meta Tag Manager <= 3.0.2 Title: Authenticated (Subscriber+) PHP Object Injection Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-1770…

Read More

Link Whisper Free Vulnerability- Authenticated (Contributor+) PHP Object Injection – CVE-2024-2693 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 26, 2024

Plugin Name: Link Whisper Free Key Information: Software Type: Plugin Software Slug: link-whisper Software Status: Active Software Author: linkwhspr Software Downloads: 449,941 Active Installs: 30,000 Last Updated: March 26, 2024 Patched Versions: 0.7.2 Affected Versions: <= 0.7.1 Vulnerability Details: Name: Link Whisper Free <= 0.7.1 Authenticated (Contributor+) PHP Object Injection Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-2693 CVSS…

Read More