CVE-2024-31211

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-31211
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31211.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-31211
Aliases
Related
Published
2024-04-04T23:15:16Z
Modified
2024-09-18T03:26:53.630774Z
Summary
[none]
Details

WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token class allows for code execution via its __destruct() magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

References

Affected packages

Debian:13 / wordpress

Package

Name
wordpress
Purl
pkg:deb/debian/wordpress?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2+dfsg1-1

Affected versions

6.*

6.1.1+dfsg1-1
6.2+dfsg1-1
6.2.1+dfsg1-1
6.2.2+dfsg1-1
6.3+dfsg1-1
6.3.1+dfsg1-1
6.3.2+dfsg1-1
6.4.1+dfsg1-1
6.4.1+dfsg1-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}