CVE-2022-2438: Broken Link Checker <= 1.11.16 - Authenticated (Admin+) PHAR Deserialization
The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$logfile' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-2438?
CVE-2022-2438 is a vulnerability found in the Broken Link Checker plugin for WordPress.
How severe is CVE-2022-2438?
CVE-2022-2438 has a severity rating of 7.2, which is considered high.
What is the affected software of CVE-2022-2438?
The affected software of CVE-2022-2438 is the Broken Link Checker plugin for WordPress versions up to and including 1.11.16.
What is the impact of CVE-2022-2438?
CVE-2022-2438 allows authenticated attackers with administrative privileges and above to call files using a PHAR wrapper, leading to potential exploitation.
How can I fix CVE-2022-2438?
To fix CVE-2022-2438, users should update the Broken Link Checker plugin for WordPress to version 1.11.17 or higher.