CVE-2022-4043

The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wp_custom_admin_interface_project:wp_custom_admin_interface:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:34

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/ffff8c83-0a59-450a-9b40-c7f3af7205fc - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/ffff8c83-0a59-450a-9b40-c7f3af7205fc - Exploit, Third Party Advisory
Summary
  • (es) El complemento WP Custom Admin Interface de WordPress anterior a 7.29 deserializa la entrada del usuario proporcionada a través de la configuración, lo que podría permitir a los usuarios con altos privilegios, como el administrador, realizar la inyección de objetos PHP cuando hay un dispositivo adecuado presente.

07 Nov 2023, 03:56

Type Values Removed Values Added
CWE CWE-502

Information

Published : 2023-01-09 23:15

Updated : 2025-04-09 20:15


NVD link : CVE-2022-4043

Mitre link : CVE-2022-4043

CVE.ORG link : CVE-2022-4043


JSON object : View

Products Affected

wp_custom_admin_interface_project

  • wp_custom_admin_interface
CWE

No CWE.