// For flags

CVE-2024-31211

Remote Code Execution in `WP_HTML_Token`

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

WordPress es una plataforma de publicación abierta para la Web. La deserialización de instancias de la clase `WP_HTML_Token` permite la ejecución de código a través de su método mágico `__destruct()`. Este problema se solucionó en WordPress 6.4.2 el 6 de diciembre de 2023. Las versiones anteriores a la 6.4.0 no se ven afectadas.

WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there being a magic method __destruct in the WP_HTML_Token class. This makes it possible for attackers to achieve remote code execution when another deserialization/PHP Object Injection vulnerability is present on the site.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-12-06 CVE Published
  • 2024-03-29 CVE Reserved
  • 2024-04-05 EPSS Updated
  • 2024-08-02 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
WordPress
Search vendor "WordPress"
Wordpress-develop
Search vendor "WordPress" for product "Wordpress-develop"
>= 6.4.0 < 6.4.2
Search vendor "WordPress" for product "Wordpress-develop" and version " >= 6.4.0 < 6.4.2"
en
Affected