CVE-2024-43354: WordPress myCred plugin <= 2.7.2 - PHP Object Injection vulnerability
Published Aug 19, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
Affected Software
1 affected component
Saad Iqbal myCred<=2.7.2
Remediation
Information
Update to 2.7.3 or a higher version.
Event History
Aug 19, 2024
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43354?
CVE-2024-43354 is rated as a critical severity vulnerability due to its potential for object injection via deserialization of untrusted data.
2
How do I fix CVE-2024-43354?
To mitigate CVE-2024-43354, upgrade the myCred plugin to version 2.7.3 or later as it addresses the vulnerability.
3
What versions are affected by CVE-2024-43354?
CVE-2024-43354 affects myCred versions up to and including 2.7.2.
4
What type of vulnerability is CVE-2024-43354?
CVE-2024-43354 is a deserialization of untrusted data vulnerability that allows for object injection.
5
Who is the vendor affected by CVE-2024-43354?
The vendor affected by CVE-2024-43354 is myCred, specifically their plugin for WordPress.