CVE Database /
CVE-2022-3366
CVE · High
CVE-2022-3366 — PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus [capability-manager-enhanced] < 2.5.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3366
|
PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus [capability-manager-enhanced] < 2.5.2 |
Deserialization of Untrusted Data |
High
7.2
|
< 2.5.2
|
2.5.2 |
2022-10-10 |
—
|
CVE-2022-3366
The PublishPress Capabilities plugin before version 2.5.2 contains a PHP Object Injection vulnerability arising from improper handling of deserialized data during import file processing. An administrator can exploit this flaw to inject arbitrary PHP objects, though the plugin itself lacks a gadget chain for direct exploitation. If other installed plugins or themes provide a suitable gadget chain, an attacker could leverage this vulnerability to execute arbitrary code, access confidential information, or remove files from the system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings