CVE-2022-2554
The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
- Affected products
- Enable Media Replace
- Shortpixel Enable Media Replace
- < 4.0.0
- Fix
- Available
- CVSS 3.1
- 4.9 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2022-10-10
CVE-2022-2554 at NVD
1 known exploit for CVE-2022-2554
Proof-of-concept code and exploit modules indexed by Sploitus