CVE-2022-3366 Information
Nov 02, 2022
cve
Description
The PublishPress Capabilities WordPress plugin before 2.5.2 PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files which could lead to PHP object injection attacks by administrators on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/72639924-e7a7-4f7d-bd50-015d05ffd4fb
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: