9.8
CVE-2022-3921
- EPSS 21.21%
- Veröffentlicht 12.12.2022 18:15:11
- Zuletzt bearbeitet 22.04.2025 15:16:01
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Listingo < 3.2.7 - Unauthenticated Arbitrary File Upload
Listingo <= 3.2.5 - Unauthenticated Arbitrary File Upload
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
Mögliche Gegenmaßnahme
Listingo: Update to version 3.2.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themographics ≫ Listingo SwPlatformwordpress Version < 3.2.7
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt
Listingo
Version
*-3.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 21.21% | 0.973 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://wpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14f
https://www.wordfence.com/threat-intel/vulnerabilities/id/62bc53ae-7cdb-491c-a315-5bf8fa80c27b