WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:46:04.743Z

Reserved: 2024-03-29T14:16:31.900Z

Link: CVE-2024-31211

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:22.177Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-04T23:15:16.333

Modified: 2024-11-21T09:13:03.010

Link: CVE-2024-31211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:00:54Z