First published: Mon Oct 31 2022(Updated: )
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ocean Extra | <2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3374 has a medium severity score due to the potential for PHP object injection vulnerabilities.
To fix CVE-2022-3374, update the Ocean Extra plugin to version 2.0.5 or later.
CVE-2022-3374 affects users of the Ocean Extra WordPress plugin versions prior to 2.0.5.
CVE-2022-3374 is a PHP object injection vulnerability caused by unserializing untrusted data.
Exploitation of CVE-2022-3374 can occur when a high privilege user imports a malicious Customizer Styling file.