CVE-2022-3334 Information
Nov 02, 2022
cve
Description
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/0e735502-eaa2-4047-949e-bc8eb6b39fc9
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: