PT-2022-16623 · WordPress · String Locator
Rasoul Jahanshahi
·
Published
2022-09-06
·
Updated
2026-04-08
·
CVE-2022-2434
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
String Locator plugin for WordPress versions up to, and including 2.5.0
Description
The issue allows deserialization of untrusted input via the
string-locator-path parameter. This enables unauthenticated users to call files using a PHAR wrapper if they can trick a site administrator into performing a specific action, such as clicking on a link, which deserializes and calls arbitrary PHP Objects. This can lead to various malicious actions if a POP chain is also present, and the attacker successfully uploads a file with the serialized payload.Recommendations
For String Locator plugin for WordPress versions up to, and including 2.5.0, update to a version higher than 2.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the
string-locator-path parameter to minimize the risk of exploitation. Avoid using the string-locator-path parameter in the affected plugin until the issue is resolved.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
String Locator