CVE-2022-3366: PublishPress Capabilities < 2.5.2 - Admin+ PHP Objection Injection
The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3366?
CVE-2022-3366 has been classified as a high severity vulnerability due to the potential for PHP object injection attacks.
How do I fix CVE-2022-3366?
To mitigate CVE-2022-3366, update the PublishPress Capabilities plugin to version 2.5.2 or higher.
Who is affected by CVE-2022-3366?
CVE-2022-3366 affects users of the PublishPress Capabilities WordPress plugin and PublishPress Capabilities Pro plugin prior to version 2.5.2.
What types of attacks can CVE-2022-3366 lead to?
CVE-2022-3366 can lead to PHP object injection attacks, particularly in multisite WordPress configurations.
Are both versions of the plugin vulnerable to CVE-2022-3366?
Yes, both the standard and pro versions of the PublishPress Capabilities plugin are vulnerable if they are below version 2.5.2.