CVE-2024-1792
The CMB2 plugin for WordPress up through version 2.10.1 contains a PHP Object Injection vulnerability in the text_datetime_timestamp_timezone field caused by unsafe deserialization of untrusted data. Authenticated users with contributor-level permissions or higher can inject malicious PHP objects, though exploitation requires a gadget chain from another installed plugin or theme. The plugin functions as a developer toolkit, and the vulnerability only manifests when a metabox is activated through code such as functions.php.
Based on public CVE data (MITRE/NVD).