CVE-2024-49699: WordPress ARPrice plugin <= 4.1.3 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.
Other sources
Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49699?
CVE-2024-49699 is classified as a critical vulnerability due to its potential for object injection attacks.
How does CVE-2024-49699 affect NotFound ARPrice?
CVE-2024-49699 allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution.
How do I fix CVE-2024-49699?
To fix CVE-2024-49699, you should upgrade NotFound ARPrice to version 4.0.4 or later to patch the vulnerability.
Is CVE-2024-49699 present in earlier versions of ARPrice?
Yes, CVE-2024-49699 affects all versions of ARPrice from n/a through 4.0.3.
What should I do if I can't update ARPrice due to compatibility issues related to CVE-2024-49699?
If updating is not an option, mitigate CVE-2024-49699 by reviewing and sanitizing user inputs to prevent untrusted data from being processed.