CVE-2022-47599: WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injection
Published Dec 20, 2023
·Updated
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.
Affected Software
1 affected component
Bitapps File Manager Wordpress<6.0.0
Remediation
Information
Update to 6.0.0 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47599?
CVE-2022-47599 is classified as a critical severity vulnerability.
2
How do I fix CVE-2022-47599?
To fix CVE-2022-47599, update the File Manager plugin to version 6.0.0 or newer.
3
What is affected by CVE-2022-47599?
CVE-2022-47599 affects the Bitapps File Manager plugin for WordPress versions prior to 6.0.0.
4
What type of vulnerability is CVE-2022-47599?
CVE-2022-47599 is a deserialization of untrusted data vulnerability.
5
Can CVE-2022-47599 be exploited remotely?
Yes, CVE-2022-47599 can be exploited remotely without authentication.