CVE-2022-2554
Enable Media Replace < 4.0.0 - Admin+ Path Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
El plugin Enable Media Replace de WordPress versiones anteriores a 4.0.0, no asegura que los archivos renombrados sean movidos a la carpeta Upload, lo que podrĂa permitir a usuarios con altos privilegios, como el administrador, moverlos fuera del directorio root de la web mediante un ataque de salto de ruta, por ejemplo
The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and including, 3.6.3. This makes it possible for authenticated attackers, with administrator-level permissions and above, to move files on the affected site's server outside of the webroot.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-27 CVE Reserved
- 2022-09-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/5872f4bf-f423-4ace-b8b6-d4cc4f6ca8d9 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Shortpixel Search vendor "Shortpixel" | Enable Media Replace Search vendor "Shortpixel" for product "Enable Media Replace" | < 4.0.0 Search vendor "Shortpixel" for product "Enable Media Replace" and version " < 4.0.0" | wordpress |
Affected
|