U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-13636

Change History

CVE Modified by Wordfence 2/24/2025 5:15:11 PM

Action Type Old Value New Value
Changed Description
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.9.2 via deserialization of untrusted input in the ot_decode function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a reservation duplicate of CVE-2024-24926. Notes: All CVE users should reference CVE-2024-24926 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Removed CVSS V3.1
Wordfence: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

								
						
Removed CWE
Wordfence: CWE-502

								
						
Removed CPE Configuration
3242907   Config Identifier: 0, OR
     
          *cpe:2.3:a:unitedthemes:brooklyn:*:*:*:*:*:wordpress:*:* versions from (excluding) 4.9.9.3

								
						
Removed Reference
Wordfence: https://themeforest.net/item/brooklyn-responsive-multipurpose-wordpress-theme/6221179

								
						
Removed Reference
Wordfence: https://unitedthemes.com/changelog/

								
						
Removed Reference
Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/id/50cc3bd5-91ee-4b57-8159-60dd700375f3?source=cve

								
						
Removed Reference Type
Wordfence: https://themeforest.net/item/brooklyn-responsive-multipurpose-wordpress-theme/6221179 Types: Product

								
						
Removed Reference Type
Wordfence: https://unitedthemes.com/changelog/ Types: Release Notes

								
						
Removed Reference Type
Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/id/50cc3bd5-91ee-4b57-8159-60dd700375f3?source=cve Types: Third Party Advisory

								
						

CVE Rejected by Wordfence 2/24/2025 5:15:11 PM

Action Type Old Value New Value