7.2
CVSSv3

CVE-2022-3374

Published: 31/10/2022 Updated: 01/11/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Ocean Extra WordPress plugin prior to 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oceanwp ocean extra