facebook facebook CVE-2021-24217 is a vulnerability in Facebook
Published on April 12, 2021

Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

NVD

Weakness Type

What is a Marshaling, Unmarshaling Vulnerability?

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE-2021-24217 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.


Products Associated with CVE-2021-24217

Want to know whenever a new CVE is published for Facebook? stack.watch will email you.

 

Exploit Probability

EPSS
6.51%
Percentile
90.98%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.