VulnerabilityModified
CVE-2022-3921
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
CRITICAL 9.8EPSS 21.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 21.20% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- themographics/listingo
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14fExploit, Third Party Advisory
- https://wpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14fExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.