CVE-2022-33900: WordPress Easy Digital Downloads plugin <= 3.0.1 - PHP Object Injection vulnerability
Published Aug 22, 2022
·Updated
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
Affected Software
2 affected components
Sandhillsdev Easy Digital Downloads Wordpress<=3.0.1
Awesomemotive Easy Digital Downloads Wordpress<=3.0.1
Remediation
Information
Update to 3.0.2 or higher version.
Event History
Aug 22, 2022
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-33900?
CVE-2022-33900 is rated as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-33900?
To fix CVE-2022-33900, update the Easy Digital Downloads plugin to version 3.0.2 or later.
3
Who is affected by CVE-2022-33900?
CVE-2022-33900 affects users of the Easy Digital Downloads plugin version 3.0.1 and earlier on WordPress.
4
What type of vulnerability is CVE-2022-33900?
CVE-2022-33900 is a PHP Object Injection vulnerability that can lead to unauthorized actions.
5
Can CVE-2022-33900 be exploited remotely?
Yes, CVE-2022-33900 can be exploited remotely without authentication, making it particularly dangerous.