CVE-2022-3417: WPtouch < 4.3.45 - Admin+ PHP Object Injection
The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the WPtouch WordPress plugin vulnerability?
The vulnerability ID for the WPtouch WordPress plugin vulnerability is CVE-2022-3417.
What is the severity of CVE-2022-3417?
The severity of CVE-2022-3417 is high, with a CVSS score of 8.8.
What is the affected software for CVE-2022-3417?
The affected software for CVE-2022-3417 is the WPtouch WordPress plugin before version 4.3.45.
What is the description of CVE-2022-3417?
CVE-2022-3417 refers to a vulnerability in the WPtouch WordPress plugin before version 4.3.45 that unserializes the content of an imported settings file, which could result in PHP object injection issues if a malicious settings file and a suitable gadget chain are present on the blog.
How can I fix CVE-2022-3417?
To fix CVE-2022-3417, you should update the WPtouch WordPress plugin to version 4.3.45 or newer.