NA

CVE-2022-3366

Published: 31/10/2022 Updated: 01/11/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The PublishPress Capabilities WordPress plugin prior to 2.5.2, PublishPress Capabilities Pro WordPress plugin prior to 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

publishpress capabilities