CVE-2024-49222: WordPress WPGuppy plugin <= 1.1.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49222?
CVE-2024-49222 is classified as a critical severity vulnerability due to its potential for remote code execution through object injection.
How do I fix CVE-2024-49222?
To fix CVE-2024-49222, update the WPGuppy plugin to the latest version beyond 1.1.0 or implement measures to validate and sanitize deserialization.
What versions of WPGuppy are affected by CVE-2024-49222?
CVE-2024-49222 affects all versions of WPGuppy up to and including version 1.1.0.
What is the impact of CVE-2024-49222 on my website?
The impact of CVE-2024-49222 can lead to unauthorized access and manipulation of the website due to object injection vulnerabilities.
Is CVE-2024-49222 related to WordPress installations?
Yes, CVE-2024-49222 affects the WPGuppy plugin which is used in WordPress installations, posing risks to those websites.