CVE-2022-2444: Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remotedata' parameter in versions up to, and including 3.7.9. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-2444.
What is the affected software?
The affected software is the Visualizer: Tables and Charts Manager for WordPress plugin for WordPress up to, and including version 3.7.9.
What is the severity of CVE-2022-2444?
The severity of CVE-2022-2444 is high with a CVSS score of 8.8.
How does the vulnerability in Visualizer: Tables and Charts Manager for WordPress plugin work?
The vulnerability in Visualizer: Tables and Charts Manager for WordPress plugin allows for deserialization of untrusted input via the 'remote_data' parameter, which can be exploited by authenticated attackers with contributor privileges and above.
Is there a fix available for CVE-2022-2444?
Yes, a fix is available for CVE-2022-2444. It is recommended to update to version 3.7.10 or higher of the Visualizer: Tables and Charts Manager for WordPress plugin.