- Description
- The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Source
- security@wordfence.com
- NVD status
- Analyzed
- Products
- auto_refresh_single_page
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-502
- Hype score
- Not currently trending
Los data brokers recopilan y venden info personal: historial financiero, salud, ubicación. Esta info es usada en ataques dirigidos (ransomware, SIM swapping) como el exploit CVE-2024-1731 de BeyondTrust. Reducí tu huella digital y protegé tus datos. #OPSEC #Privacidad.
@FK94SECURITY
21 Feb 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Si sos founder o inversor, tu cuenta de correo personal NO debería ser la misma que usás para gestionar tus inversiones o la infraestructura de tu empresa. CVE-2024-1731 es un recordatorio de que el riesgo de ser targeteado es real. Separá tus identidades digitales.
@FK94SECURITY
20 Feb 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rymera:auto_refresh_single_page:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "73B0BE79-BF20-4EA4-8AAC-AFA6AB4BCFDA",
"versionEndIncluding": "1.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]