CVE-2024-30225: WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability
Published Mar 28, 2024
·Updated
Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.
Affected Software
1 affected component
WP Engine WP Migrate<=2.6.10
Remediation
Information
Update to 2.6.11 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30225?
CVE-2024-30225 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-30225?
To fix CVE-2024-30225, upgrade WP Migrate to version 2.6.11 or higher.
3
What software is affected by CVE-2024-30225?
CVE-2024-30225 affects WP Migrate versions up to and including 2.6.10.
4
What type of vulnerability is CVE-2024-30225?
CVE-2024-30225 is a deserialization of untrusted data vulnerability.
5
Are there any workarounds for CVE-2024-30225?
There are no known workarounds for CVE-2024-30225; updating the affected software is essential.