CVE-2021-24217: Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain
Published Apr 12, 2021
·Updated
The runaction function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.
Affected Software
1 affected component
Facebook Facebook Wordpress<3.0.0
Event History
Apr 12, 2021
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24217.
2
What is the severity of CVE-2021-24217?
The severity of CVE-2021-24217 is high with a severity value of 8.1.
3
What is the affected software of CVE-2021-24217?
The affected software of CVE-2021-24217 is the Facebook for WordPress plugin before version 3.0.0.
4
What is the risk of CVE-2021-24217?
CVE-2021-24217 poses a risk of Object Injection vulnerability and potential remote code execution.
5
How can I fix CVE-2021-24217?
To fix CVE-2021-24217, update the Facebook for WordPress plugin to version 3.0.0 or later.