Medium severity5.5NVD Advisory· Published Apr 4, 2024· Updated Jun 17, 2026
CVE-2024-31211
CVE-2024-31211
Description
WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token class allows for code execution via its __destruct() magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<6.4.0+ 1 more
- (no CPE)range: <6.4.0
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=6.4.0,<6.4.2
- Range: >= 6.4.0 < 6.4.2
- osv-coords2 versions
>= 6.4.0, < 6.4.2+ 1 more
- (no CPE)range: >= 6.4.0, < 6.4.2
- (no CPE)range: >= 6.4.0, < 6.4.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.