CVE-2024-2006: Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.7 via deserialization of untrusted input in the outpostshortcodemetaboxmarkup function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2006?
CVE-2024-2006 has a moderate severity due to the potential for PHP Object Injection that can lead to remote code execution.
How do I fix CVE-2024-2006?
To fix CVE-2024-2006, update the Post Grid, Slider & Carousel Ultimate plugin to version 1.6.8 or later.
Which versions are affected by CVE-2024-2006?
CVE-2024-2006 affects all versions of the Post Grid, Slider & Carousel Ultimate plugin up to and including version 1.6.7.
What is the impact of CVE-2024-2006?
The impact of CVE-2024-2006 includes the potential exploitation through PHP Object Injection, leading to unauthorized code execution.
Is it safe to use older versions of the Post Grid, Slider & Carousel Ultimate plugin after CVE-2024-2006?
No, it is not safe to use older versions as they are vulnerable to exploitation, and users should update immediately.