CVE-2024-32835: WordPress Export and Import Users and Customers plugin <= 2.5.3 - Deserialization of untrusted data vulnerability
Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32835?
CVE-2024-32835 is classified as a high severity vulnerability due to its potential for remote exploitation through untrusted data deserialization.
How do I fix CVE-2024-32835?
To fix CVE-2024-32835, update the WebToffee Import Export WordPress Users plugin to version 2.5.4 or later.
Which versions of the WebToffee Import Export WordPress Users plugin are affected by CVE-2024-32835?
CVE-2024-32835 affects versions of the WebToffee Import Export WordPress Users plugin from n/a through 2.5.3.
What happens if I do not patch CVE-2024-32835?
If CVE-2024-32835 is not patched, attackers could exploit the vulnerability to execute arbitrary code on the affected WordPress site.
Is CVE-2024-32835 specific to any other plugins?
Yes, CVE-2024-32835 also affects the WebToffee WordPress Export and Import Users and Customers plugin versions up to 2.5.3.