PT-2025-6609 · WordPress · The Puzzles | Wp Magazine / Review With Store Wordpress Theme + Rtl

Lucio Sá

·

Published

2025-02-13

·

Updated

2025-02-24

·

CVE-2024-13770

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress versions up to, and including, 4.2.4
Description The issue concerns PHP Object Injection via deserialization of untrusted input in the 'view more posts' AJAX action. This allows unauthenticated attackers to inject a PHP Object. However, without a POP chain present in the vulnerable software or an additional plugin/theme, the impact is limited. If a POP chain is present, it could enable actions like deleting arbitrary files, retrieving sensitive data, or executing code, depending on the chain. The software has been removed from the repository, and no update is available.
Recommendations For versions up to, and including, 4.2.4, consider finding a replacement software as the developer has removed it from the repository and no update is available. As a temporary workaround, consider disabling the 'view more posts' AJAX action until a replacement software is implemented. Restrict access to sensitive data and files to minimize potential damage in case of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13770

Affected Products

The Puzzles | Wp Magazine / Review With Store Wordpress Theme + Rtl