QID 154155
Date Published: 2024-04-08
QID 154155: WordPress Remote Code Execution Vulnerability (CVE-2024-31211)
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
The vulnerability allows for remote code execution via the __destruct() magic method of the WP_HTML_Token class when instances of this class are unserialized. An attacker could exploit this vulnerability to execute arbitrary code on the target system.
Affected Versions:
WordPress from 6.4 to 6.4.1
QID Detection Logic:
This QID sends an HTTP GET request and checks for vulnerable version of WordPress running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to 6.4.2 or latest version of WordPress to remediate these vulnerabilities. For more information regarding these vulnerabilities please visit Github Advisory.
Vendor References
CVEs related to QID 154155
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitHub Advisory |
|
||
| WordPress |
|