First published: Mon Jul 18 2022(Updated: )
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Visualizer | <3.7.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2444.
The affected software is the Visualizer: Tables and Charts Manager for WordPress plugin for WordPress up to, and including version 3.7.9.
The severity of CVE-2022-2444 is high with a CVSS score of 8.8.
The vulnerability in Visualizer: Tables and Charts Manager for WordPress plugin allows for deserialization of untrusted input via the 'remote_data' parameter, which can be exploited by authenticated attackers with contributor privileges and above.
Yes, a fix is available for CVE-2022-2444. It is recommended to update to version 3.7.10 or higher of the Visualizer: Tables and Charts Manager for WordPress plugin.