PT-2022-15017 · Mariadb+1 · Mariadb+1
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 5.8.3
WordPress versions prior to 3.7.37
Description
The issue concerns a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection.
Recommendations
For versions prior to 5.8.3, update to version 5.8.3 or later.
For versions prior to 3.7.37, update to version 3.7.37 or later.
As a general measure, keep auto-updates enabled to ensure the latest security patches are applied.
Exploit
Fix
Special Elements Injection
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mariadb
Wordpress