CVE · High

CVE-2024-1792 — CMB2 [cmb2] < 2.11.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1792 CMB2 [cmb2] < 2.11.0 Deserialization of Untrusted Data High 7.5 < 2.11.0 2.11.0 2024-04-03

CVE-2024-1792

The CMB2 plugin for WordPress up through version 2.10.1 contains a PHP Object Injection vulnerability in the text_datetime_timestamp_timezone field caused by unsafe deserialization of untrusted data. Authenticated users with contributor-level permissions or higher can inject malicious PHP objects, though exploitation requires a gadget chain from another installed plugin or theme. The plugin functions as a developer toolkit, and the vulnerability only manifests when a metabox is activated through code such as functions.php.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.