Sploitus

CVE-2022-3374

1 known exploit for CVE-2022-3374

The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

Affected products
Ocean Extra
Oceanwp Ocean Extra
< 2.0.5
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
1.1% (64th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2022-10-31
CVE-2022-3374 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-3374

Proof-of-concept code and exploit modules indexed by Sploitus