CVE-2024-29136: WordPress Tourfic plugin <= 2.11.17 - PHP Object Injection vulnerability
Published Mar 19, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.
Affected Software
3 affected components
Themefic Tourfic Wordpress<2.11.19
Themefic Tourfic<=2.11.17
WordPress Tourfic plugin<=2.11.17
Remediation
Information
Update to 2.11.19 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29136?
CVE-2024-29136 has a medium severity rating due to the potential for deserialization of untrusted data, which could lead to code execution or data manipulation.
2
How do I fix CVE-2024-29136?
To fix CVE-2024-29136, update the Themefic Tourfic plugin to version 2.11.18 or later to mitigate the vulnerability.
3
What versions of Tourfic are affected by CVE-2024-29136?
CVE-2024-29136 affects Themefic Tourfic versions from n/a to 2.11.17.
4
What type of vulnerability is CVE-2024-29136?
CVE-2024-29136 is a deserialization of untrusted data vulnerability.
5
What can happen if CVE-2024-29136 is exploited?
If exploited, CVE-2024-29136 could allow an attacker to execute arbitrary code or alter data within the affected application.