CVE-2022-2439: Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization
The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2439?
CVE-2022-2439 has a high severity level due to the potential for remote code execution and data manipulation.
How do I fix CVE-2022-2439?
To fix CVE-2022-2439, update the Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin to version 3.3.4 or later.
Who is affected by CVE-2022-2439?
Authenticated administrative users of the Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin up to version 3.3.3 are affected by CVE-2022-2439.
What is the impact of CVE-2022-2439?
The impact of CVE-2022-2439 includes unauthorized access and potential exploitation through deserialization of untrusted input.
Is CVE-2022-2439 still an issue in newer versions?
CVE-2022-2439 has been addressed in version 3.3.4 and later of the plugin, so users should ensure they are using the latest version.