CVE-2022-3335: Kadence WooCommerce Email Designer < 1.5.7 - Admin+ PHP Objection Injection
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Kadence WooCommerce Email Designer plugin?
The vulnerability ID of the Kadence WooCommerce Email Designer plugin is CVE-2022-3335.
What is the title of the vulnerability?
The title of the vulnerability is 'The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an …'.
What is the severity of CVE-2022-3335?
The severity of CVE-2022-3335 is high, with a severity value of 7.2.
What software is affected by CVE-2022-3335?
The Kadence WooCommerce Email Designer WordPress plugin versions up to and excluding 1.5.7 are affected by CVE-2022-3335.
How can the vulnerability CVE-2022-3335 be exploited?
The vulnerability CVE-2022-3335 can be exploited by importing a malicious file that contains a suitable gadget chain, leading to PHP object injection issues.