CVE-2024-30221: WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30221?
The severity of CVE-2024-30221 is classified as high due to the potential for remote code execution through deserialization of untrusted data.
How do I fix CVE-2024-30221?
To fix CVE-2024-30221, update the Sunshine Photo Cart plugin to version 3.1.2 or later.
What versions of Sunshine Photo Cart are affected by CVE-2024-30221?
All versions of Sunshine Photo Cart from its release up to and including version 3.1.1 are affected by CVE-2024-30221.
Is CVE-2024-30221 a zero-day vulnerability?
CVE-2024-30221 is not a zero-day vulnerability as it has been publicly disclosed and a patch is available.
What impact does CVE-2024-30221 have on WordPress sites?
CVE-2024-30221 can allow attackers to execute arbitrary code on affected WordPress sites, leading to full site compromise.