7.2

CVE-2022-3380

Exploit

Customizer Export/Import < 0.9.5 - Admin+ PHP Objection Injection

Customizer Export/Import <= 0.9.4 - Authenticated (Administrator+) PHP Object Injection

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Mögliche Gegenmaßnahme
Customizer Export/Import: Update to version 0.9.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FastlinemediaCustomizer Export/import SwPlatformwordpress Version < 0.9.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Customizer Export/Import
Version *-0.9.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.13% 0.621
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://wpscan.com/vulnerability/a42272a2-f9ce-4aab-9a94-8a4d85008746
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/72fadfa8-4b53-4661-8b6c-69cdb79d3fd7
Third Party Advisory