CVE-2024-2694

Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.


We have discovered 58,540 live websites that are affected by CVE-2024-2694.

Run a Free Instant Scan




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Domains58,540 live websites (64% of BeTheme install base)
Vulnerable Versions
  • from 0 through 27.5.6
Vulnerable Versions Count319 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 30, 2024
  • Updated - Aug 30, 2024

Credits

  • Francesco Carlucci (finder)

Website Distribution by Country

Number of websites using CVE-2024-2694
United States12,309 websites



Germany7,298 websites
Italy4,078 websites
Brazil3,067 websites
France2,947 websites
Spain2,005 websites
Poland1,914 websites
GB1,889 websites
Netherlands1,706 websites
Russia1,408 websites

Website Distribution by TLD

Number of websites using CVE-2024-2694
.com21,089 websites
.de4,359 websites
.it3,000 websites
.com.br2,983 websites
.org1,798 websites
.nl1,511 websites
.fr1,490 websites
.pl1,462 websites
.ru1,126 websites
.co.uk1,123 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2694

Top websites that are affected by CVE-2024-2694. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.nl United States*,***
******.fr France**,***
****************************.com United States**,***
**********.com United States**,***
************.com United States**,***
**********.com United States**,***
***************.com United States**,***
***********.de Germany**,***
***********.com Canada***,***
*******.**.ke Kenya***,***
See full domain list

FAQ

CVE-2024-2694 is Deserialization of Untrusted Data in BeTheme
A total of 58,540 websites have been identified as vulnerable to CVE-2024-2694, based on global website indexing conducted by WebTechSurvey.
The BeTheme is affected by the CVE-2024-2694 vulnerability.
BeTheme versions up to and including 27.5.6 are vulnerable to CVE-2024-2694.