7.2
CVE-2022-4680
- EPSS 1.2%
- Veröffentlicht 30.01.2023 21:15:11
- Zuletzt bearbeitet 27.03.2025 20:15:17
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Revive Old Posts <= 9.0.10 - Authenticated (Admin+) PHP Object Injection
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Mögliche Gegenmaßnahme
Revive Social – Social Media Auto Post and Scheduling Automation Plugin: Update to version 9.0.11, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Revive Social – Social Media Auto Post and Scheduling Automation Plugin
Version
*-9.0.10
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Revive ≫ Revive Old Posts SwPlatformwordpress Version < 9.0.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.785 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|