PT-2022-21789 · WordPress · Phlox
Nguyen Duy Quoc Khanh
·
Published
2022-12-12
·
Updated
2023-02-01
·
CVE-2022-3359
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shortcodes and extra features for Phlox theme WordPress plugin versions prior to 2.10.7
Description
The issue arises from the unserialize of the content of an imported file, which could lead to PHP object injection when a user imports a malicious file and a suitable gadget chain is present on the blog. This occurs when a user, intentionally or not, imports a malicious file.
Recommendations
For versions prior to 2.10.7, update to version 2.10.7 or later to resolve the issue. As a temporary workaround, consider restricting the import functionality to trusted users or files until the update is applied. Avoid using the import feature with untrusted files until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phlox