9.8
CVSSv3

CVE-2024-13410

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00257 | KEV: Not Included
Published: 19/03/2025 Updated: 19/03/2025

Vulnerability Summary

PHP Object Injection in CozyStay and TinySalt WordPress Plugins via Deserialization

WordPress plugins CozyStay (up to version 1.7.0) and TinySalt (up to version 3.9.0) have a PHP Object Injection vulnerability in their 'ajax_handler' function. This security issue allows unauthenticated attackers to inject PHP Objects through deserialization of untrusted input. While no direct exploit chain is currently known in these plugins, the vulnerability could become serious if another installed plugin or theme contains a Property Oriented Programming (POP) chain. In such a scenario, an attacker might potentially delete files, access sensitive information, or execute code depending on the specific POP chain present in the additional installed software.

Vulnerable Product Search on Vulmon Subscribe to Product

loftocean cozystay - hotel booking wordpress theme

loftocean tinysalt - personal food blog wordpress theme