CVE-2024-5085
CVE-2024-5085 is a PHP Object Injection vulnerability affecting the Hash Form – Drag & Drop Form Builder plugin for WordPress, versions 1.1.0 and below. This vulnerability stems from the insecure deserialization of untrusted input within the 'process_entry' function, potentially allowing unauthenticated attackers to inject PHP Objects. While the vulnerable plugin itself lacks a known POP chain, the presence of a POP chain in other installed plugins or themes could be exploited. This could lead to severe consequences such as arbitrary file deletion, sensitive data retrieval, or even remote code execution. With an SVRS of 34, this vulnerability requires monitoring, especially in environments with numerous plugins. Although the CVSS score is 0, the potential for exploitation via external POP chains raises the overall risk profile. Immediate mitigation steps should be considered if other installed components introduce a POP chain.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.