PT-2022-21789 · WordPress · Phlox

Nguyen Duy Quoc Khanh

·

Published

2022-12-12

·

Updated

2023-02-01

·

CVE-2022-3359

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shortcodes and extra features for Phlox theme WordPress plugin versions prior to 2.10.7
Description The issue arises from the unserialize of the content of an imported file, which could lead to PHP object injection when a user imports a malicious file and a suitable gadget chain is present on the blog. This occurs when a user, intentionally or not, imports a malicious file.
Recommendations For versions prior to 2.10.7, update to version 2.10.7 or later to resolve the issue. As a temporary workaround, consider restricting the import functionality to trusted users or files until the update is applied. Avoid using the import feature with untrusted files until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2022-3359

Affected Products

Phlox