Skip to main content
HIGH

CVE-2022-4324

CVSS v3

7.2

HIGH

EPSS Score

1.2 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

Technical details

Published
2023-01-02

Frequently asked questions

What is CVE-2022-4324?

The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

Is CVE-2022-4324 actively exploited?

Active exploitation of CVE-2022-4324 has not been confirmed. The EPSS score is 1.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-4324?

CVE-2022-4324 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2022-4324 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key