CVE-2021-24857 is a critical PHP Object Injection vulnerability affecting the ToTop Link WordPress plugin through version 1.7.1, stemming from its use of base64 encoded user input with the unserialize() function. This flaw carries a CVSS score of 9.8, indicating a critical risk with network-based, low-complexity attacks that require no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and potential for significant impact, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.1CPE matchmatch criteria | cpe:2.3:a:nocean:totop_link:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.