CVE-2022-3861




The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage, and importfromclipboard functions. This makes it possible for authenticated attackers, with contributor level permissions and above to inject a PHP Object. The additional presence of a POP chain would make it possible for attackers to execute code, retrieve sensitive data, delete files, etc..



We have discovered 7,368 live websites that are affected by CVE-2022-3861.

Contact us to get more info




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 26.5.1.4
Total Vulnerable Versions512
Vulnerable Domains7,368 live websites (55.05% of BeTheme install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-3861 and the relative popularity of websites


Details

  • Published - Nov 21, 2022

Credits

  • Julien Ahrens (finder)




Countries

United States1,746 websites



Germany991 websites
France545 websites
Italy437 websites
Spain299 websites
GB278 websites
Netherlands242 websites
Brazil233 websites
Poland232 websites
Canada162 websites

TLDs

.com2,685 websites
.de676 websites
.org515 websites
.it272 websites
.fr251 websites
.nl190 websites
.com.br178 websites
.pl177 websites
.net161 websites
.co.uk126 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-3861 through included software libraries and plugins.



References


Websites affected by CVE-2022-3861

Top websites that are affected by CVE-2022-3861. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*********.nl Netherlands*,***
***.*************.com United States**,***
*******.org Spain**,***
***.buzz United States**,***
*****************.com United States**,***
***.******.fr France**,***
***.****************************.com United States**,***
**********.com United States**,***
**********.com United States**,***
*************.com United States**,***
See full domain list