First published: Mon Jan 02 2023(Updated: )
The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Videousermanuals White Label Cms | <2.5 | |
<2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4302 is rated as high with a score of 7.2.
CVE-2022-4302 exploits the vulnerability by allowing high-privilege users such as admin to perform PHP Object Injection through unserializing user input provided via the settings.
To address CVE-2022-4302, users should update the White Label CMS WordPress plugin to version 2.5 or higher.