CVE-2024-30226: WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerability
Published Mar 28, 2024
·Updated
Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.
Affected Software
2 affected components
WPDeveloper BetterDocs<=3.3.3
WPDeveloper Betterdocs Wordpress<3.3.4
Remediation
Information
Update to 3.3.4 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·04:57 AM
Data Sourced
via MITRE·04:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30226?
CVE-2024-30226 is classified as a high severity vulnerability due to the potential for remote code execution via untrusted data deserialization.
2
What software is affected by CVE-2024-30226?
CVE-2024-30226 affects the WPDeveloper BetterDocs plugin versions up to and including 3.3.3.
3
How do I fix CVE-2024-30226?
To mitigate CVE-2024-30226, it is recommended to update the BetterDocs plugin to the latest version provided by WPDeveloper.
4
What type of vulnerability is CVE-2024-30226?
CVE-2024-30226 is a deserialization of untrusted data vulnerability which can lead to severe security implications.
5
Is there a workaround for CVE-2024-30226 besides updating?
Currently, the most effective resolution for CVE-2024-30226 is to update to a secure version as no reliable workaround exists.