CVE-2024-24797: WordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object Injection
Published Feb 12, 2024
·Updated
Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.
Affected Software
1 affected component
G5plus Ere Recently Viewed Wordpress<2.0
Event History
Feb 12, 2024
CVE Published
via MITRE·07:19 AM
Data Sourced
via MITRE·07:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24797?
CVE-2024-24797 has been classified with a high severity due to its potential impact on system security.
2
How do I fix CVE-2024-24797?
To mitigate CVE-2024-24797, update the ERE Recently Viewed – Essential Real Estate Add-On to version 1.4 or later.
3
What is the impact of CVE-2024-24797?
CVE-2024-24797 allows for deserialization of untrusted data, potentially leading to remote code execution.
4
Which versions are affected by CVE-2024-24797?
CVE-2024-24797 affects versions of ERE Recently Viewed – Essential Real Estate Add-On from n/a through 1.3.
5
Is user authentication required to exploit CVE-2024-24797?
CVE-2024-24797 can be exploited without user authentication, making it particularly critical.