ZeroHour

CVE-2022-4794

PoC
CVSS 3.1
7.5 high
EPSS
<1%p55
Published
()
Modified
Description

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

Vendors
getaawp
Products
amazon affiliate wordpress plugin
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.