CVE-2022-2433

Source
https://cve.org/CVERecord?id=CVE-2022-2433
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2433.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2433
Published
2022-09-06T17:18:56Z
Modified
2026-07-15T01:48:52.739944754Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization
Details

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'almrepeatersexport' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "5.5.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-502"
    ],
    "cna_assigner": "Wordfence",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2433.json"
}
References

Affected packages

Git / github.com/ajaxloadmore/ajax-load-more

Affected ranges

Type
GIT
Repo
https://github.com/ajaxloadmore/ajax-load-more
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2433.json"