8.8

CVE-2022-3417

Exploit

WPtouch < 4.3.45 - Admin+ PHP Object Injection

WPtouch <= 4.3.44 - Authenticated (Administrator+) PHP Object Injection

The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog.
Mögliche Gegenmaßnahme
WPtouch – Make your WordPress Website Mobile-Friendly: Update to version 4.3.45, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BravenewcodeWptouch SwPlatformwordpress Version < 4.3.45
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WPtouch – Make your WordPress Website Mobile-Friendly
Version *-4.3.44
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.556
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/55772932-eebd-475b-b5df-e80fab288ee5
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/7148e182-858c-42b1-b9db-9b7a267483e1
Third Party Advisory