First published: Wed May 18 2022(Updated: )
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-estore Popup Box | <=2.1.2 | |
<=2.1.2 |
Update to 2.2 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29445 is classified as a high severity Local File Inclusion vulnerability.
To fix CVE-2022-29445, update the Popup Box plugin to version 2.1.3 or later.
CVE-2022-29445 affects users with the Popup Box plugin version 2.1.2 or earlier installed on their WordPress site.
Exploitation of CVE-2022-29445 requires authenticated access with an administrator or higher role.
CVE-2022-29445 can lead to unauthorized access to sensitive files on the server, potentially compromising the website.