CVE-2022-3380

HIGH

WordPress Customizer Export/Import <0.9.5 - Code Injection

Title source: llm

Description

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Scores

CVSS v3 7.2
EPSS 0.0094
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

wpbeaverbuilder/customizer_export\/import < 0.9.5

Timeline

Published Oct 31, 2022
Tracked Since Feb 18, 2026