6.8

CVE-2022-29448

WordPress Herd Effects plugin <= 5.2 - Local File Inclusion (LFI) vulnerability

Herd Effects <= 5.2 - Local File Inclusion

Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.
Mögliche Gegenmaßnahme
Social Proof Popups & Real-Time Notifications – Herd Effects: Update to version 5.2.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wow-estoreHerd Effects SwPlatformwordpress Version <= 5.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Social Proof Popups & Real-Time Notifications – Herd Effects
Version *-5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.576
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
audit@patchstack.com 6.8 0.9 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://patchstack.com/database/vulnerability/mwp-herd-effect/wordpress-herd-effects-plugin-5-2-local-file-inclusion-lfi-vulnerability
Third Party Advisory
https://wordpress.org/plugins/mwp-herd-effect/#developers
Product
https://www.wordfence.com/threat-intel/vulnerabilities/id/8acb86fa-50b4-45b3-9bf8-ef65679b85ac
Third Party Advisory