Code injection in WordPress - CVE-2022-21663

 

Code injection in WordPress - CVE-2022-21663

Published: January 7, 2022 / Updated: January 11, 2022


Vulnerability identifier: #VU59289
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21663
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to improper input validation in some multisite installations. A remote user with Super Admin role can bypass explicit/additional hardening and inject certain objects.

Successful exploitation of this vulnerability may result in complete compromise of web application.


Affected software

WordPress
wordpress (Debian package)
wordpress
Fedora

How to mitigate CVE-2022-21663

Install updates from vendor's website.

WordPress - addressed in versions 3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3
wordpress (Debian package) - addressed in versions 5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1
wordpress - addressed in versions 5.1.12-1.el7, 5.8.3-1.fc34, 5.8.3-1.fc35

External References

Related Security Bulletins