CVE-2022-3359

The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:averta:shortcodes_and_extra_features_for_phlox_theme:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 03:51

Type Values Removed Values Added
CWE CWE-502

23 Jan 2023, 14:15

Type Values Removed Values Added
Summary The Shortcodes and extra features for Phlox WordPress plugin through 2.10.5 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

15 Dec 2022, 17:46

Type Values Removed Values Added
First Time Averta
Averta shortcodes And Extra Features For Phlox Theme
References (MISC) https://wpscan.com/vulnerability/08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6 - (MISC) https://wpscan.com/vulnerability/08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:averta:shortcodes_and_extra_features_for_phlox_theme:*:*:*:*:*:wordpress:*:*

12 Dec 2022, 18:18

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-12 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3359

Mitre link : CVE-2022-3359

CVE.ORG link : CVE-2022-3359


JSON object : View

Products Affected

averta

  • shortcodes_and_extra_features_for_phlox_theme
CWE

No CWE.