CVE-2024-30222: WordPress ARMember plugin <= 4.0.26 - PHP Object Injection vulnerability
Published Mar 28, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
Affected Software
3 affected components
Repute Infosystems ARMember<=4.0.26
WordPress ARMember Plugin<=4.0.26
reputeinfosystems Armember Wordpress<4.0.27
Remediation
Information
Update to 4.0.27 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30222?
CVE-2024-30222 has a medium severity rating reflecting the potential for unauthorized access due to deserialization of untrusted data.
2
How do I fix CVE-2024-30222?
To fix CVE-2024-30222, upgrade ARMember to version 4.0.27 or later to patch the vulnerability.
3
Who is affected by CVE-2024-30222?
CVE-2024-30222 affects all versions of Repute Infosystems ARMember from n/a up to and including 4.0.26.
4
What type of vulnerability is CVE-2024-30222?
CVE-2024-30222 is categorized as a deserialization of untrusted data vulnerability.
5
Can CVE-2024-30222 be exploited remotely?
Yes, CVE-2024-30222 can potentially be exploited remotely, allowing attackers to manipulate the application’s behavior.