CVE-2021-24579
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- bold-themes/bold page builder
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/08edce3f-2746-4886-8439-76e44ec76fa8Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/08edce3f-2746-4886-8439-76e44ec76fa8Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.