Sploitus

CVE-2022-0316

12 known exploits for CVE-2022-0316

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

Aidreform Project Aidreform
All versions
Chimpgroup Bolster
All versions
Chimpgroup Spikes
All versions
Chimpgroup Westand
< 2.1
Club-theme Project Club-theme
All versions
Footysquare Project Footysquare
All versions
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
2.1% (81th percentile)
NVD status
Modified
Published
2023-01-23
CVE-2022-0316 at NVD
Authoritative description, scoring and affected products

12 known exploits for CVE-2022-0316

Proof-of-concept code and exploit modules indexed by Sploitus