CVE-2022-2357
PoC —CVSS 3.1
7.5 high
EPSS
1%p71
Published
()
Modified
Description
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
- Vendors
- wsm downloader project
- Products
- wsm downloader
- Ecosystems
- WordPress
- Weakness
- CWE-552
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.