The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Shahriar0822
Shahriar0822 the Next |
|
CPEs | cpe:2.3:a:shahriar0822:the_next:*:*:*:*:*:*:*:* | |
Vendors & Products |
Shahriar0822
Shahriar0822 the Next |
|
Metrics |
ssvc
|
Thu, 08 Aug 2024 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. | |
Title | The Next <= 1.1.0 - Authenticated (Contributor+) PHP Object Injection | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-08T15:31:54.978Z
Reserved: 2024-08-06T14:50:51.944Z
Link: CVE-2024-7561

Updated: 2024-08-08T15:31:51.082Z

Status : Awaiting Analysis
Published: 2024-08-08T02:15:39.017
Modified: 2024-08-08T13:04:18.753
Link: CVE-2024-7561

No data.