PT-2022-16649 · WordPress · Feed Them Social

Rasoul Jahanshahi

·

Published

2022-07-18

·

Updated

2023-10-24

·

CVE-2022-2437

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress versions up to, and including 2.9.8.5
Description The issue allows deserialization of untrusted input via the fts url parameter. This enables unauthenticated attackers to call files using a PHAR wrapper, which can deserialize the data and call arbitrary PHP Objects to perform malicious actions, provided a POP chain is also present. The attack requires the successful upload of a file with a serialized payload.
Recommendations For Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress versions up to, and including 2.9.8.5, update to a version higher than 2.9.8.5 to resolve the issue. As a temporary workaround, consider restricting access to the fts url parameter to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-2437

Affected Products

Feed Them Social