CVE-2022-29445: WordPress Popup Box plugin <= 2.1.2 - Authenticated Local File Inclusion (LFI) vulnerability
Published May 18, 2022
·Updated
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
Affected Software
1 affected component
Wow-estore Popup Box Wordpress<=2.1.2
Remediation
Information
Update to 2.2 or higher version.
Event History
May 18, 2022
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-29445?
CVE-2022-29445 is classified as a high severity Local File Inclusion vulnerability.
2
How do I fix CVE-2022-29445?
To fix CVE-2022-29445, update the Popup Box plugin to version 2.1.3 or later.
3
Who is affected by CVE-2022-29445?
CVE-2022-29445 affects users with the Popup Box plugin version 2.1.2 or earlier installed on their WordPress site.
4
What type of access is required to exploit CVE-2022-29445?
Exploitation of CVE-2022-29445 requires authenticated access with an administrator or higher role.
5
What impact does CVE-2022-29445 have on my website?
CVE-2022-29445 can lead to unauthorized access to sensitive files on the server, potentially compromising the website.