ZeroHour

CVE-2022-1788

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p54
Published
()
Modified
Description

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

Vendors
change uploaded file permissions project
Products
change uploaded file permissions
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.