CVSS v3
8.8
HIGH
EPSS Score
3.3 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage, and importfromclipboard functions. This makes it possible for authenticated attackers, with contributor level permissions and above to inject a PHP Object. The additional presence of a POP chain would make it possible for attackers to execute code, retrieve sensitive data, delete files, etc..
Technical details
- Published
- 2022-11-21
Frequently asked questions
What is CVE-2022-3861?
The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage, and importfromclipboard functions. This makes it possible for authenticated attackers, with contributor level permissions and above to inject a PHP Object. The additional presence of a POP chain would make it possible for attackers to execute code, retrieve sensitive data, delete files, etc..
Is CVE-2022-3861 actively exploited?
Active exploitation of CVE-2022-3861 has not been confirmed. The EPSS score is 3.3%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-3861?
CVE-2022-3861 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2022-3861 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).