The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
History

Thu, 08 May 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Infinitumform
Infinitumform geo Controller
Weaknesses CWE-502
CPEs cpe:2.3:a:infinitumform:geo_controller:*:*:*:*:*:wordpress:*:*
Vendors & Products Infinitumform
Infinitumform geo Controller

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-05-01T06:00:02.438Z

Updated: 2024-08-01T20:12:07.872Z

Reserved: 2024-04-10T14:38:11.224Z

Link: CVE-2024-3591

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.872Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-01T06:15:21.887

Modified: 2025-05-08T18:25:09.343

Link: CVE-2024-3591

cve-icon Redhat

No data.