7.2
CVE-2022-4680
- EPSS 1.05%
- Veröffentlicht 30.01.2023 21:15:11
- Zuletzt bearbeitet 27.03.2025 20:15:17
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Revive Old Posts – Social Media Auto Post and Scheduling Plugin < 9.0.11 - PHP Object Injection
Revive Old Posts <= 9.0.10 - Authenticated (Admin+) PHP Object Injection
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Mögliche Gegenmaßnahme
Revive Social – Social Media Auto Post and Scheduling Automation Plugin: Update to version 9.0.11, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Revive ≫ Revive Old Posts SwPlatformwordpress Version < 9.0.11
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Revive Social – Social Media Auto Post and Scheduling Automation Plugin
Version
*-9.0.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.597 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
https://wpscan.com/vulnerability/f4197386-975d-4e53-8fc9-9425732da9af
https://www.wordfence.com/threat-intel/vulnerabilities/id/6322e9be-ad71-4a91-ab9f-760107d920be