CVE-2022-0320
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.99% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- wpdeveloper/essential addons for elementor
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/0d02b222-e672-4ac0-a1d4-d34e1ecf4a95Third Party Advisory
- https://wpscan.com/vulnerability/0d02b222-e672-4ac0-a1d4-d34e1ecf4a95Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.