The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via deserialization of untrusted input via the vimeography_duplicate_gallery_serialized in the duplicate_gallery function. This makes it possible for authenticated attackers attackers, with contributor access or higher, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
History

Tue, 11 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Davekiss
Davekiss vimeography
Weaknesses CWE-502
CPEs cpe:2.3:a:davekiss:vimeography:*:*:*:*:*:wordpress:*:*
Vendors & Products Davekiss
Davekiss vimeography

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-11T13:52:07.980Z

Reserved: 2024-01-23T14:59:55.276Z

Link: CVE-2024-0825

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.603Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-05T02:15:25.653

Modified: 2025-03-11T16:45:26.630

Link: CVE-2024-0825

cve-icon Redhat

No data.