CVE-2024-30224: WordPress WholesaleX plugin <= 1.3.2 - Unauthenticated PHP Object Injection vulnerability
Published Mar 28, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.
Affected Software
3 affected components
wpxpo Wholesalex Wordpress<1.3.3
Wholesale Team WholesaleX<=1.3.2
WordPress WholesaleX<=1.3.2
Remediation
Information
Update to 1.3.3 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:02 AM
Data Sourced
via MITRE·05:02 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30224?
CVE-2024-30224 has a high severity rating due to its potential to allow arbitrary code execution via deserialization of untrusted data.
2
How do I fix CVE-2024-30224?
To fix CVE-2024-30224, upgrade WholesaleX to version 1.3.3 or later to mitigate the vulnerability.
3
What versions of WholesaleX are affected by CVE-2024-30224?
CVE-2024-30224 affects WholesaleX versions from n/a up to and including 1.3.2.
4
What type of vulnerability is CVE-2024-30224?
CVE-2024-30224 is classified as a deserialization of untrusted data vulnerability.
5
Can CVE-2024-30224 be exploited remotely?
Yes, CVE-2024-30224 can potentially be exploited remotely if the application is accessible over the internet.