CVE-2022-3361
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via Shortcodes
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (../../) to access and include files outside of the intended directory. If an attacker can successfully upload a php file then remote code execution via inclusion may also be possible. Note: for users with less than administrative capabilities, /wp-admin access needs to be enabled for that user in order for this to be exploitable by those users.
El complemento Ultimate Member para WordPress es vulnerable al directory traversal en versiones hasta la 2.5.0 incluida debido a una validación de entrada insuficiente en el atributo 'template' utilizado en los shortcodes. Esto hace posible que los atacantes con privilegios administrativos proporcionen rutas arbitrarias utilizando el recorrido (../../) para acceder e incluir archivos fuera del directorio deseado. Si un atacante puede cargar con éxito un archivo php, también es posible la ejecución remota de código mediante inclusión.
Nota: para los usuarios con capacidades inferiores a las administrativas, el acceso /wp-admin debe estar habilitado para ese usuario para que pueda explotarlo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-29 CVE Reserved
- 2022-10-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3361 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/H4de5-7/vulnerabilities/blob/main/CVE-2022-3361.md | 2024-08-03 | |
https://www.yuque.com/docs/share/23f988ad-1402-42f2-b8d2-c7a87a4022bd | 2024-08-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimatemember Search vendor "Ultimatemember" | Ultimate Member Search vendor "Ultimatemember" for product "Ultimate Member" | <= 2.5.0 Search vendor "Ultimatemember" for product "Ultimate Member" and version " <= 2.5.0" | wordpress |
Affected
|