CVE-2022-2557: WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and Deletion
Published Aug 22, 2022
·Updated
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
Affected Software
1 affected component
RadiusTheme Team - Wordpress Team Members Showcase Wordpress<4.1.2
Event History
Aug 22, 2022
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-2557.
2
What is the severity rating of CVE-2022-2557?
CVE-2022-2557 has a severity rating of 8.8.
3
How can an authenticated user exploit CVE-2022-2557?
An authenticated user can exploit CVE-2022-2557 by using a path traversal vector to download arbitrary files from the server.
4
Which version of the Team WordPress plugin is affected by CVE-2022-2557?
The Team WordPress plugin before version 4.1.2 is affected by CVE-2022-2557.
5
Is there a fix available for CVE-2022-2557?
Yes, updating the Team WordPress plugin to version 4.1.2 or later will fix CVE-2022-2557.