← back
CVE-2021-24217CWE-502

Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.5%
exploitation probability
3.5%top 12% of all CVEs
observed exploitation
nono source reports it
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.