CVE-2022-3359
—CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
Description
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
- Vendors
- averta
- Products
- shortcodes and extra features for phlox theme
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.