CVE-2024-10957
The UpdraftPlus: WP Backup & Migration Plugin for WordPress contains a PHP Object Injection flaw affecting versions 1.23.8 through 1.24.11 in the 'recursive_unserialized_replace' function, where untrusted data is unserialized without proper validation. An unauthenticated attacker can exploit this vulnerability by triggering a search and replace operation to inject malicious PHP objects, though the exploitation impact depends on whether additional plugins or themes with usable Property-Oriented Programming chains are present on the site. If such a chain exists, an attacker could potentially delete files, access sensitive information, or execute arbitrary code. The vulnerability was fixed in version 1.24.12.
Based on public CVE data (MITRE/NVD).