CVE-2022-0316
23.01.2023, 15:15
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.Enginsight
| Vendor | Product | Version |
|---|---|---|
| aidreform_project | aidreform | - |
| chimpgroup | bolster | - |
| chimpgroup | spikes | - |
| chimpgroup | westand | 𝑥 < 2.1 |
| club-theme_project | club-theme | - |
| footysquare_project | footysquare | - |
| pixfill | kings_club | - |
| soundblast_project | soundblast | - |
| spikes-black_project | spikes-black | - |
| statfort_project | statfort | - |
𝑥
= Vulnerable software versions