7.2

CVE-2022-29447

WordPress Hover Effects plugin <= 2.1 - Authenticated Local File Inclusion (LFI) vulnerability

Hover Effects – easily create any hover effect <= 2.1 - Authenticated Local File Inclusion

Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
Mögliche Gegenmaßnahme
Hover Effects – easily create any hover effect: Update to version 2.1.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wow-companyHover Effects SwPlatformwordpress Version <= 2.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Hover Effects – easily create any hover effect
Version *-2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.576
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
audit@patchstack.com 6.8 0.9 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://patchstack.com/database/vulnerability/hover-effects/wordpress-hover-effects-plugin-2-1-authenticated-local-file-inclusion-lfi-vulnerability
Third Party Advisory
Release Notes
https://wordpress.org/plugins/hover-effects/#developers
Product
Release Notes
https://www.wordfence.com/threat-intel/vulnerabilities/id/e82cdfab-8090-4979-81b6-5b860e9ae187
Third Party Advisory