First published: Mon Aug 29 2022(Updated: )
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xplodedthemes Wpide | <3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2261 is high with a CVSS score of 7.2.
The affected software of CVE-2022-2261 is the WPIDE WordPress plugin version up to but not including 3.0.
CVE-2022-2261 is a Local File Inclusion (LFI) vulnerability.
To fix CVE-2022-2261, update the WPIDE WordPress plugin to version 3.0 or newer.
You can find more information about CVE-2022-2261 at the following reference: <a href='https://wpscan.com/vulnerability/f6091d7b-97b5-42f2-b2f4-09a0fe6d5a21'>https://wpscan.com/vulnerability/f6091d7b-97b5-42f2-b2f4-09a0fe6d5a21</a>