Unrated severityNVD Advisory· Published Apr 4, 2024· Updated Aug 2, 2024
Remote Code Execution in `WP_HTML_Token`
CVE-2024-31211
Description
WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token class allows for code execution via its __destruct() magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
Affected products
3- osv-coords2 versions
>= 6.4.0, < 6.4.2+ 1 more
- (no CPE)range: >= 6.4.0, < 6.4.2
- (no CPE)range: >= 6.4.0, < 6.4.2
- WordPress/wordpress-developv5Range: >= 6.4.0 < 6.4.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/WordPress/wordpress-develop/security/advisories/GHSA-m257-q4m5-j653mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.