Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection
2023-01-02 00:00
thinhnguyen1337Strategic Overview
StatusPatched in 6.5.6
Affected PluginAnalyticator
Affected Version
<= 6.5.5CVSS7.2High
CVE
CVE-2022-4323Vulnerability Overview
The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.5 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. The additional presence of a POP chain in the vulnerable plugin may allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Technical Analysis
REMEDIATION: Update to version 6.5.6, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C