The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infinitumform
Infinitumform geo Controller |
|
Weaknesses | CWE-502 | |
CPEs | cpe:2.3:a:infinitumform:geo_controller:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Infinitumform
Infinitumform geo Controller |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-01T06:00:02.438Z
Updated: 2024-08-01T20:12:07.872Z
Reserved: 2024-04-10T14:38:11.224Z
Link: CVE-2024-3591

Updated: 2024-08-01T20:12:07.872Z

Status : Analyzed
Published: 2024-05-01T06:15:21.887
Modified: 2025-05-08T18:25:09.343
Link: CVE-2024-3591

No data.