First published: Mon Feb 06 2023(Updated: )
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
HUSKY – Products Filter for WooCommerce | <1.3.2 | |
<1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4489 is a vulnerability in the HUSKY WordPress plugin before version 1.3.2 that allows high privilege users to perform PHP Object Injection.
CVE-2022-4489 occurs when the plugin unserializes user input provided via the settings.
The severity of CVE-2022-4489 is high, with a CVSS score of 7.2.
The HUSKY WordPress plugin versions up to and excluding 1.3.2 are affected by CVE-2022-4489.
To fix CVE-2022-4489, it is recommended to update the HUSKY WordPress plugin to version 1.3.2 or later.