CVE-2022-4101
The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 29.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 29.37% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- images optimize and upload cf7 project/images optimize and upload cf7
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/2ce4c837-c62c-41ac-95ca-54bb1a6d1eebExploit, Third Party Advisory
- https://wpscan.com/vulnerability/2ce4c837-c62c-41ac-95ca-54bb1a6d1eebExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.