CVE-2021-24579 is a PHP Object Injection vulnerability in the Bold Page Builder WordPress plugin versions prior to 3.1.6. It allows authenticated attackers to pass unvalidated user input to the unserialize() function. This vulnerability has a CVSS score of 8.8 (High), indicating a significant risk of remote code execution (RCE) if other plugins provide suitable gadgets. While no active exploitation, public exploits, or significant community discussion have been observed, the potential for RCE warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.6CPE matchmatch criteria | cpe:2.3:a:bold-themes:bold_page_builder:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.