CVE · High

CVE-2024-10957 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.24.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10957 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.24.12 Deserialization of Untrusted Data High 8.8 < 1.24.12 1.24.12 2025-01-03

CVE-2024-10957

The UpdraftPlus: WP Backup & Migration Plugin for WordPress contains a PHP Object Injection flaw affecting versions 1.23.8 through 1.24.11 in the 'recursive_unserialized_replace' function, where untrusted data is unserialized without proper validation. An unauthenticated attacker can exploit this vulnerability by triggering a search and replace operation to inject malicious PHP objects, though the exploitation impact depends on whether additional plugins or themes with usable Property-Oriented Programming chains are present on the site. If such a chain exists, an attacker could potentially delete files, access sensitive information, or execute arbitrary code. The vulnerability was fixed in version 1.24.12.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.