CVE · High

CVE-2021-24217 — Meta pixel for WordPress [official-facebook-pixel] < 3.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24217 Meta pixel for WordPress [official-facebook-pixel] < 3.0.0 Deserialization of Untrusted Data High 8.1 < 3.0.0 3.0.0 2021-03-25

CVE-2021-24217

The Facebook for WordPress plugin prior to version 3.0.0 contains an object injection vulnerability in its run_action function, which processes unserialized user-controlled input without proper validation. An attacker could exploit this by supplying specially crafted PHP objects, and leverage an available magic method within the plugin code to execute arbitrary remote code on affected systems.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.