6.8

CVE-2022-29448

Herd Effects <= 5.2 - Local File Inclusion

Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.
Mögliche Gegenmaßnahme
Social Proof Popups & Real-Time Notifications – Herd Effects: Update to version 5.2.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Social Proof Popups & Real-Time Notifications – Herd Effects
Version * - 5.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wow-estoreHerd Effects SwPlatformwordpress Version <= 5.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.761
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
audit@patchstack.com 6.8 0.9 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.