7.5

CVE-2022-4794

Exploit

AAWP < 3.12.3 - Unsafe URL Handling

Amazon Affiliate <= 3.12.2 - Reflected File Download

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
Mögliche Gegenmaßnahme
Amazon Affiliate: Update to version 3.12.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetaawpAmazon Affiliate Wordpress Plugin SwPlatformwordpress Version < 3.12.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Amazon Affiliate
Version *-3.12.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.517
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/feb4580d-df15-45c8-b59e-ad406e4b064c
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/e94f9cde-5e8b-4d68-8ede-12d678a370ed
Third Party Advisory