CRITICAL
Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read
Published Apr 25, 2022
9.8
CRITICALCVSS 3.1
EPSS 21.88%
Description
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique
Affected products
- Vendor n/a Product Admin Word Count Column Defaultunknown
Affected
- 2.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Admin Word Count Column | unknown | Affected
|
- ≤ 2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24707 Advisory
- https://packetstormsecurity.com/files/166476/ x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://wpscan.com/vulnerability/6293b319-dc4f-4412-9d56-55744246c990 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24707 | Advisory | |
| https://packetstormsecurity.com/files/166476/ | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://wpscan.com/vulnerability/6293b319-dc4f-4412-9d56-55744246c990 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 25, 2022
Updated Aug 3, 2024
Reserved Apr 19, 2022
Link CVE-2022-1390
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data