CVE-2022-3679 – Starter Templates by Kadence WP < 1.2.17 - Admin+ PHP Object Injection
https://notcve.org/view.php?id=CVE-2022-3679
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. El complemento Starter Templates by Kadence WP de WordPress anterior a 1.2.17 deserializa el contenido de un archivo importado, lo que podría provocar problemas de inyección de objetos PHP cuando un administrador importa (intencionalmente o no) un archivo malicioso y una cadena de gadgets adecuada está presente en el blog. The Starter Templates by Kadence WP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.16 via the 'import_customizer_options' function. This allows authenticated users with administratior-level capabilities to inject a PHP Object. No POP chain is present in the vulnerable plugin. • https://wpscan.com/vulnerability/ec4b9bf7-71d6-4528-9dd1-cc7779624760 • CWE-502: Deserialization of Untrusted Data •