First published: Mon Feb 12 2024(Updated: )
Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mage-people Event Manager And Tickets Selling Plugin For Woocommerce | <4.1.2 |
Update to 4.1.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-24796 is classified as critical due to the potential for remote code execution through deserialization of untrusted data.
To fix CVE-2024-24796, update the MagePeople Event Manager and Tickets Selling Plugin for WooCommerce to version 4.1.2 or later.
CVE-2024-24796 affects versions of the MagePeople Event Manager and Tickets Selling Plugin for WooCommerce prior to 4.1.2.
The impact of CVE-2024-24796 includes the possibility of attackers executing arbitrary code on vulnerable WordPress installations.
Yes, CVE-2024-24796 is considered exploitable in the wild, which increases the urgency for users to apply the necessary updates.