// For flags

CVE-2022-2943

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read

Severity Score

4.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.

El plugin WordPress Infinite Scroll - Ajax Load More para Wordpress es vulnerable a una lectura de archivos arbitrarios en versiones hasta 5.5.3, incluyéndola, debido a una insuficiente comprobación de la ruta del archivo en la función alm_repeaters_export(). Esto hace posible a atacantes autenticados, con privilegios administrativos, descargar archivos arbitrarios alojados en el servidor que pueden contener contenido confidencial, como el archivo wp-config.php.

*Credits: Muhammad Zeeshan
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-22 CVE Reserved
  • 2022-08-22 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Connekthq
Search vendor "Connekthq"
Ajax Load More
Search vendor "Connekthq" for product "Ajax Load More"
< 5.5.4
Search vendor "Connekthq" for product "Ajax Load More" and version " < 5.5.4"
wordpress
Affected