CVE-2022-3359high

CVE-2022-3359: high-severity vulnerability in Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme < 2.10.7 - PHP Objection Injection

Published · Updated

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Related CVEs — Shortcodes and extra features for Phlox theme

In the same product, most dangerous first.