logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-3366

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-3366

Description:
The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.
Last updated date:
11/01/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/01/2022
Reference url to background

https://wpscan.com/vulnerability/72639924-e7a7-4f7d-bd50-015d05ffd4fb

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy