PT-2022-16697 · WordPress · The Visualizer: Tables/Charts Manager For Wordpress

Rasoul Jahanshahi

·

Published

2022-07-18

·

Updated

2023-10-24

·

CVE-2022-2444

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Visualizer: Tables and Charts Manager for WordPress versions up to, and including 3.7.9
Description The issue concerns deserialization of untrusted input via the remote data parameter. This allows authenticated attackers with contributor privileges and above to call files using a PHAR wrapper, which can deserialize the data and call arbitrary PHP Objects. These objects can be used to perform various malicious actions if a POP chain is also present. The attack requires the successful upload of a file with a serialized payload.
Recommendations For versions up to, and including 3.7.9, update to a version higher than 3.7.9 to mitigate the risk. As a temporary workaround, consider restricting access to the remote data parameter until a patch is available. Avoid using the remote data parameter in the affected plugin until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-2444

Affected Products

The Visualizer: Tables/Charts Manager For Wordpress