CVE-2024-54367: WordPress ForumWP plugin <= 2.1.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54367?
CVE-2024-54367 is categorized as a critical vulnerability due to its potential for object injection through deserialization.
How do I fix CVE-2024-54367?
To fix CVE-2024-54367, update ForumWP to version 2.1.1 or later as it addresses the deserialization issue.
What are the implications of CVE-2024-54367 in ForumWP?
CVE-2024-54367 allows attackers to exploit object injection vulnerabilities, potentially gaining unauthorized access to sensitive data or executing malicious code.
Which versions of ForumWP are affected by CVE-2024-54367?
CVE-2024-54367 affects all versions of ForumWP up to and including version 2.1.0.
Can CVE-2024-54367 affect my WordPress site?
Yes, if you are using the ForumWP plugin version 2.1.0 or earlier on your WordPress site, it is vulnerable to CVE-2024-54367.