CVE-2022-3374
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
- Affected products
- Ocean Extra
- Oceanwp Ocean Extra
- < 2.0.5
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.1% (64th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2022-10-31
CVE-2022-3374 at NVD
1 known exploit for CVE-2022-3374
Proof-of-concept code and exploit modules indexed by Sploitus