CVE-2022-3357: Smart Slider 3 < 3.5.1.11 - PHP Object Injection
The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3357?
CVE-2022-3357 is rated as a critical vulnerability due to its potential for PHP object injection issues.
How do I fix CVE-2022-3357?
To fix CVE-2022-3357, update the Smart Slider 3 WordPress plugin to version 3.5.1.11 or later.
What causes the vulnerability CVE-2022-3357?
CVE-2022-3357 is caused by the unserialisation of untrusted input in the Smart Slider 3 plugin during file import.
Who is affected by CVE-2022-3357?
Users of the Smart Slider 3 WordPress plugin prior to version 3.5.1.11 are affected by CVE-2022-3357.
Can CVE-2022-3357 lead to a site compromise?
Yes, CVE-2022-3357 can lead to a site compromise if an attacker successfully imports a malicious file.