CVE-2022-3380: Customizer Export/Import < 0.9.5 - Admin+ PHP Objection Injection
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3380?
CVE-2022-3380 is classified as a medium severity vulnerability due to the potential for PHP object injection when importing malicious files.
How do I fix CVE-2022-3380?
To fix CVE-2022-3380, update the Customizer Export/Import WordPress plugin to version 0.9.5 or later.
What causes CVE-2022-3380?
CVE-2022-3380 is caused by the plugin's practice of unserializing imported file content without proper validation.
Who is affected by CVE-2022-3380?
Any WordPress site using the Customizer Export/Import plugin prior to version 0.9.5 is affected by CVE-2022-3380.
Can I safely use the Customizer Export/Import plugin if I have an older version?
It is not safe to use the Customizer Export/Import plugin in older versions due to the risk of PHP object injection as outlined in CVE-2022-3380.