CVE-2022-29446: WordPress Counter Box plugin <= 1.1.1 - Authenticated Local File Inclusion (LFI) vulnerability
Published May 19, 2022
·Updated
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
Affected Software
1 affected component
Wow-Company Counter Box WordPress<=1.1.1
Remediation
Information
Update to 1.2 or higher version.
Event History
May 19, 2022
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-29446?
The severity of CVE-2022-29446 is high with a severity value of 7.2.
2
What is the affected software for CVE-2022-29446?
The affected software for CVE-2022-29446 is Wow-Company's Counter Box plugin version <= 1.1.1 at WordPress.
3
How does the LFI vulnerability in CVE-2022-29446 work?
The LFI vulnerability in CVE-2022-29446 allows an authenticated user with administrator or higher role to include and read local files on the server.
4
Are there any fixes available for CVE-2022-29446?
Yes, there is a fix available for CVE-2022-29446. Please refer to the provided references for more information.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-29446?
The Common Weakness Enumeration (CWE) ID for CVE-2022-29446 is 552.