Vulnerability Description
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Soflyy | Wp All Import | < 4.9.8 |
Related Weaknesses (CWE)
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0099a8d7-827d-4215-9a2Third Party Advisory
- https://www.wpallimport.com/Product
FAQ
What is CVE-2024-9664?
CVE-2024-9664 is a vulnerability with a CVSS score of 7.2 (HIGH). The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it p...
How severe is CVE-2024-9664?
CVE-2024-9664 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9664?
Check the references section above for vendor advisories and patch information. Affected products include: Soflyy Wp All Import.