PT-2022-15017 · Mariadb+1 · Mariadb+1

·

CVE-2022-21663

·

Published

2022-01-06

·

Updated

2024-03-06

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.8.3 WordPress versions prior to 3.7.37
Description The issue concerns a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection.
Recommendations For versions prior to 5.8.3, update to version 5.8.3 or later. For versions prior to 3.7.37, update to version 3.7.37 or later. As a general measure, keep auto-updates enabled to ensure the latest security patches are applied.

Exploit

Fix

Special Elements Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2022-21663
BIT-WORDPRESS-MULTISITE-2022-21663
CVE-2022-21663
DLA-2884-1
DSA-5039-1
GHSA-JMMQ-M8P8-332H

Affected Products

Mariadb
Wordpress