1 results (0.001 seconds)
CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

CVE-2024-13889 – WordPress Importer <= 0.8.3 - Authenticated (Administrator+) PHP Object Injection
https://notcve.org/view.php?id=CVE-2024-13889
25 Mar 2025 — The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP... • https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L602 • CWE-502: Deserialization of Untrusted Data •