CVE-2024-2694

Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.


We have discovered 87,358 live websites that are affected by CVE-2024-2694.

Test my site




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Domains87,358 live websites (78.84% of BeTheme install base)
Vulnerable Versions
  • from 0 through 27.5.6
Vulnerable Versions Count594 versions ( 97.70% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 30, 2024
  • Updated - Aug 30, 2024

Credits

  • Francesco Carlucci (finder)

CVE-2024-2694 usage by Country

United States25,651 websites



Germany12,779 websites
France5,267 websites
Brazil3,401 websites
Italy3,191 websites
Poland2,879 websites
GB2,513 websites
Spain2,452 websites
Netherlands2,210 websites
Russia1,838 websites

CVE-2024-2694 usage by TLD

.com32,643 websites
.de6,464 websites
.com.br4,489 websites
.fr2,992 websites
.it2,842 websites
.org2,654 websites
.pl2,280 websites
.nl2,235 websites
.co.uk1,659 websites
.ru1,481 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2694

Top websites that are affected by CVE-2024-2694. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.nl United States*,***
***********.com United States*,***
*****.com United States**,***
*****************.com United States**,***
**********.nl Germany**,***
******.fr France**,***
****************************.com United States**,***
**********.com United States**,***
**********.com United States**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-2694 is Deserialization of Untrusted Data in BeTheme
A total of 87,358 websites have been identified as vulnerable to CVE-2024-2694, discovered through global website indexing conducted by WebTechSurvey.
BeTheme is susceptible to CVE-2024-2694 vulnerability.
BeTheme versions before, and including, 27.5.6 are vulnerable to CVE-2024-2694.