First published: Sun Apr 07 2024(Updated: )
Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Product Designer | >=n/a<=1.0.32 | |
WordPress Product Designer | <=1.0.32 |
Update to 1.0.33 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31277 is classified as a high severity vulnerability due to its potential for remote code execution via deserialization of untrusted data.
To fix CVE-2024-31277, update the PickPlugins Product Designer to the latest version beyond 1.0.32.
CVE-2024-31277 affects PickPlugins Product Designer and WordPress Product Designer versions up to 1.0.32.
CVE-2024-31277 can be exploited by attackers to perform remote code execution through crafted input.
As of now, no specific public exploit for CVE-2024-31277 has been reported, but its nature makes it a significant risk.