7.5
CVE-2022-4794
- EPSS 0.8%
- Veröffentlicht 30.01.2023 21:15:12
- Zuletzt bearbeitet 28.03.2025 15:15:43
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
AAWP < 3.12.3 - Unsafe URL Handling
Amazon Affiliate <= 3.12.2 - Reflected File Download
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
Mögliche Gegenmaßnahme
Amazon Affiliate: Update to version 3.12.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getaawp ≫ Amazon Affiliate Wordpress Plugin SwPlatformwordpress Version < 3.12.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Amazon Affiliate
Version
*-3.12.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.8% | 0.517 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
https://wpscan.com/vulnerability/feb4580d-df15-45c8-b59e-ad406e4b064c
https://www.wordfence.com/threat-intel/vulnerabilities/id/e94f9cde-5e8b-4d68-8ede-12d678a370ed