CVE-2024-32603: WordPress WooBuddy plugin <= 3.4.20 - PHP Object Injection vulnerability
Published Apr 18, 2024
·Updated
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
Affected Software
3 affected components
Themekraft WooBuddy<=3.4.20
WordPress WooBuddy plugin<=3.4.20
Themekraft Buddypress Woocommerce My Account Integration Wordpress<3.4.21
Remediation
Information
Update to 3.4.21 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32603?
CVE-2024-32603 has been classified as a high severity deserialization vulnerability.
2
How do I fix CVE-2024-32603?
To fix CVE-2024-32603, update the ThemeKraft WooBuddy plugin to version 3.4.21 or later.
3
Which versions of WooBuddy are affected by CVE-2024-32603?
CVE-2024-32603 affects WooBuddy versions up to and including 3.4.20.
4
What type of vulnerability is CVE-2024-32603?
CVE-2024-32603 is a deserialization of untrusted data vulnerability.
5
What impact does CVE-2024-32603 have on my website?
CVE-2024-32603 could allow an attacker to exploit the vulnerability to execute arbitrary code on the affected site.