CVE-2022-3416: WPtouch < 4.3.45 - Admin+ Arbitrary File Upload
Published Jan 9, 2023
·Updated
The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Affected Software
1 affected component
Bravenewcode Wptouch Wordpress<4.3.45
Event History
Jan 9, 2023
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3416.
2
What is the severity of CVE-2022-3416?
The severity of CVE-2022-3416 is high with a severity value of 7.2.
3
What is the affected software?
The affected software is the WPtouch WordPress plugin before version 4.3.45.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by high privilege users, such as admin, to upload arbitrary files on the server.
5
Is there a fix available for CVE-2022-3416?
Yes, the fix for CVE-2022-3416 is to update WPtouch plugin to version 4.3.45 or later.