Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2433
HistorySep 06, 2022 - 6:15 p.m.

Deserialization of untrusted data

2022-09-0618:15:00
PRIOn knowledge base
www.prio-n.com
2
wordpress
infinite scroll
ajax load more
untrusted data
deserialization
vulnerability
phar wrapper
arbitrary php objects
malicious actions
pop chain
file upload

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the ‘alm_repeaters_export’ parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

CPENameOperatorVersion
ajax_load_morelt5.5.4

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

Related for PRION:CVE-2022-2433