CVE-2024-3591

CVE-2024-3591: WordPress Geo Controller < 8.6.5 - PHP Object Injection

Vendor Unknown
Product Geo Controller
Published May 1, 2024
Last update August 1, 2024

CVSS base score

What the vulnerability does

01Description

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Key dates

02Disclosure timeline

May 1, 2024 CVE published
August 1, 2024 Record updated