CVE · High

CVE-2022-3380 — Customizer Export/Import [customizer-export-import] < 0.9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3380 Customizer Export/Import [customizer-export-import] < 0.9.5 Deserialization of Untrusted Data High 7.2 < 0.9.5 0.9.5 2022-10-06

CVE-2022-3380

The Customizer Export/Import plugin through version 0.9.4 contains a PHP Object Injection vulnerability caused by unsafe deserialization of data from imported files. Administrators with access to the import function can inject malicious PHP objects into the system. While the plugin itself lacks a gadget chain to exploit this directly, the presence of a usable chain in other installed plugins or themes could potentially enable attackers to execute arbitrary code, exfiltrate sensitive information, or remove files from the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.