CVE-2022-3366
PublishPress Capabilities < 2.5.2 - Admin+ PHP Objection Injection
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.2EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
31 oct 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Unknown · PublishPress Capabilities ProUnknown · PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →