8.8

CVE-2022-3679

Exploit

Starter Templates by Kadence WP < 1.2.17 - Admin+ PHP Object Injection

Starter Templates by Kadence WP <= 1.2.16 - Authenticated (Admin+) PHP Object Injection

The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Mögliche Gegenmaßnahme
Kadence Starter Templates — Predesigned Website Templates: Update to version 1.2.17, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KadencewpStarter Templates SwPlatformwordpress Version <= 1.2.17
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Kadence Starter Templates — Predesigned Website Templates
Version *-1.2.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.556
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/ec4b9bf7-71d6-4528-9dd1-cc7779624760
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/72eda38d-34e9-4a0e-a760-a9b991e590de
Third Party Advisory