Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2945

Опубликовано: 06 сент. 2022
Источник: nvd
CVSS3: 4.9
CVSS3: 2.7
EPSS Низкий

Описание

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:connekthq:ajax_load_more:*:*:*:*:*:wordpress:*:*
Версия до 5.5.3 (включая)

EPSS

Процентиль: 79%
0.01292
Низкий

4.9 Medium

CVSS3

2.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 2.7
github
больше 3 лет назад

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.

EPSS

Процентиль: 79%
0.01292
Низкий

4.9 Medium

CVSS3

2.7 Low

CVSS3

Дефекты

CWE-22