CVE-2022-0779
08.06.2022, 10:15
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
Vendor | Product | Version |
---|---|---|
user-meta | user_meta_user_profile_builder_and_user_management | 𝑥 < 2.4.4 |
𝑥
= Vulnerable software versions