PT-2022-16623 · WordPress · String Locator

·

CVE-2022-2434

·

Published

2022-09-06

·

Updated

2026-04-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions String Locator plugin for WordPress versions up to, and including 2.5.0
Description The issue allows deserialization of untrusted input via the string-locator-path parameter. This enables unauthenticated users to call files using a PHAR wrapper if they can trick a site administrator into performing a specific action, such as clicking on a link, which deserializes and calls arbitrary PHP Objects. This can lead to various malicious actions if a POP chain is also present, and the attacker successfully uploads a file with the serialized payload.
Recommendations For String Locator plugin for WordPress versions up to, and including 2.5.0, update to a version higher than 2.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the string-locator-path parameter to minimize the risk of exploitation. Avoid using the string-locator-path parameter in the affected plugin until the issue is resolved.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2434

Affected Products

String Locator