{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-3335","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","dateUpdated":"2025-05-09T19:04:09.994Z","dateReserved":"2022-09-27T00:00:00.000Z","datePublished":"2022-10-25T00:00:00.000Z"},"containers":{"cna":{"title":"Kadence WooCommerce Email Designer < 1.5.7 - Admin+ PHP Objection Injection","providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2022-10-25T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog."}],"affected":[{"vendor":"Unknown","product":"Kadence WooCommerce Email Designer","versions":[{"version":"1.5.7","status":"affected","lessThan":"1.5.7","versionType":"custom"}]}],"references":[{"url":"https://wpscan.com/vulnerability/39514705-c887-4a02-a77b-36e1dcca8f5d"}],"credits":[{"lang":"en","value":"Nguyen Duy Quoc Khanh"}],"problemTypes":[{"descriptions":[{"type":"CWE","description":"CWE-502 Deserialization of Untrusted Data","cweId":"CWE-502","lang":"en"}]}],"x_generator":"WPScan CVE Generator","source":{"discovery":"EXTERNAL"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T01:07:06.557Z"},"title":"CVE Program Container","references":[{"url":"https://wpscan.com/vulnerability/39514705-c887-4a02-a77b-36e1dcca8f5d","tags":["x_transferred"]}]},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.2,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"HIGH","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-05-09T19:03:30.607673Z","id":"CVE-2022-3335","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-09T19:04:09.994Z"}}]}}