WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:46:04.743Z
Reserved: 2024-03-29T14:16:31.900Z
Link: CVE-2024-31211
Updated: 2024-05-23T19:01:22.177Z
Status : Awaiting Analysis
Published: 2024-04-04T23:15:16.333
Modified: 2024-11-21T09:13:03.010
Link: CVE-2024-31211
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:00:54Z
Weaknesses