s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4838

📛 CVE Title

ConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object Injection

Description

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Overview

State
PUBLISHED
Assigner (CNA)
Wordfence
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
CWE-502
Reserved
2024-05-13
Published
2024-05-16 13:05 UTC
Last updated
2026-04-08 18:37 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4838.json
Linked Threat
CVE-2024-4838 — ConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object Injection

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-44420
Assigner
Wordfence
Published
May 16, 2024, 11:05:27 AM
Updated
Apr 8, 2026, 4:37:16 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
2.2700
Vendors
Brainstorm Force
Products
ConvertPlus (0 ≤3.5.26)
ConvertPlus (* ≤3.5.26)
Aliases
GHSA-43c9-25jg-rxm4

ENISA description: The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
Brainstorm Force ConvertPlus 0 (affected)

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2024-4838 no local data 2026-06-06 14:33 UTC

Flagged vendors

    Remediations (18)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.microsoft.com

      These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.

      2026-08-05 12:27 UTC
    • web:www.microsoft.com

      Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...

      2026-08-05 12:27 UTC
    • web:learn.microsoft.com

      Use the DISM tool to fix problems that prevent Windows Update from installing successfully.

      2026-08-05 12:27 UTC
    • web:www.tenable.com

      Microsoft addresses 70 CVEs in its December 2024 Patch Tuesday release, 16 rated critical including CVE - 2024 -49138, a zero-day that was exploited in the wild.

      2026-08-05 12:27 UTC
    • web:catalog.update.microsoft.com

      Welcome to the Microsoft Update Catalog site. We want your feedback! Visit our newsgroup or send us an email to provide us with your thoughts and suggestions. To get started using the site, enter in your search terms in the Search box above or visit our FAQ for search tips. |Newsgroup|Send us your feedback

      2026-08-05 12:27 UTC
    • web:learn.microsoft.com

      Learning path Learn how Microsoft supports secure software development as part of a cybersecurity solution - Training Secure software development means integrating security into each phase of your development lifecycle, from requirements analysis to maintenance. Microsoft provides many services that can help you develop more secure code and deploy a more secure application in the cloud. This ...

      2026-08-05 12:27 UTC
    • web:www.vicarius.io

      Join Vicarius, a global leader in advanced vulnerability remediation . Explore opportunities with one of the fastest growing cybersecurity companies.

      2026-08-05 12:27 UTC
    • Wordfence remediation: ConvertPlus
      Wordfence

      Update to version 3.5.26.1, or a newer patched version

      2026-06-06 14:33 UTC
    • web:www.tenable.com

      Synopsis The remote host is missing several patches. Description The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date. Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled ...

      2026-05-22 10:39 UTC
    • web:www.veritas.com

      Install Oracle 19c Windows October 2024 patch This section includes the following patches:

      2026-05-22 10:39 UTC
    • web:support.servicenow.com

      Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...

      2026-05-22 10:39 UTC
    • web:dailysecurityreview.com

      CVE -2025-48384 represents a practical and actively exploited vector that leverages Git submodule handling and carriage return mismatches to achieve arbitrary code execution. CISA's addition of the flaw to the KEV catalog and the September 15 remediation deadline underscore the urgency for patching across federal and enterprise environments.

      2026-05-22 10:39 UTC
    • web:nvd.nist.gov

      Information Technology Laboratory National Vulnerability Database Vulnerabilities

      2026-05-22 10:39 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 10:39 UTC
    • web:robertsspaceindustries.com

      Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...

      2026-05-22 10:39 UTC
    • web:source.android.com

      This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.

      2026-05-22 10:39 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-05-22 10:39 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-05-22 10:39 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-4838.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4838",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-16T15:50:07.680350Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:54:31.748Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:55:09.895Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16f5a104-dce0-4249-91b9-67f99cce16d3?source=cve"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.convertplug.com/plus/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ConvertPlus",
              "vendor": "Brainstorm Force",
              "versions": [
                {
                  "lessThanOrEqual": "3.5.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "haidv35"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-08T16:37:16.264Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16f5a104-dce0-4249-91b9-67f99cce16d3?source=cve"
            },
            {
              "url": "https://www.convertplug.com/plus/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-05-15T00:00:00.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "ConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object Injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2024-4838",
        "datePublished": "2024-05-16T11:05:27.037Z",
        "dateReserved": "2024-05-13T16:21:48.419Z",
        "dateUpdated": "2026-04-08T16:37:16.264Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }