The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.4 via deserialization of untrusted input from the play_podcast_data post meta. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
History

Tue, 15 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Hammadh pay.ht Make Your Blog Posts Accessible With Text To Speech Audio
CPEs cpe:2.3:a:hammadh:pay.ht_make_your_blog_posts_accessible_with_text_to_speech_audio:*:*:*:*:*:*:*:*
Vendors & Products Hammadh pay.ht Make Your Blog Posts Accessible With Text To Speech Audio
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Hammadh
Hammadh play.ht
Weaknesses CWE-502
CPEs cpe:2.3:a:hammadh:play.ht:*:*:*:*:*:wordpress:*:*
Vendors & Products Hammadh
Hammadh play.ht

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-04-15T15:21:30.464Z

Reserved: 2024-02-22T17:58:09.964Z

Link: CVE-2024-1772

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.977Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-13T16:15:27.040

Modified: 2025-04-03T13:11:01.240

Link: CVE-2024-1772

cve-icon Redhat

No data.