CVE-2022-38140: WordPress SEO Plugin by Squirrly SEO Plugin <= 12.1.10 is vulnerable to Arbitrary File Upload
Published Nov 28, 2022
·Updated
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
Affected Software
1 affected component
Squirrly SEO Plugin by Squirrly SEO WordPress<=12.1.10
Remediation
Information
Update to 12.1.11 or a higher version.
Event History
Nov 28, 2022
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38140?
CVE-2022-38140 is considered a high severity vulnerability due to the potential for arbitrary file uploads by authenticated users.
2
How do I fix CVE-2022-38140?
To mitigate CVE-2022-38140, upgrade the Squirrly SEO plugin to a version higher than 12.1.10.
3
Who is affected by CVE-2022-38140?
CVE-2022-38140 affects users of the Squirrly SEO plugin version 12.1.10 and earlier on WordPress who have contributor-level access.
4
What type of vulnerability is CVE-2022-38140?
CVE-2022-38140 is an arbitrary file upload vulnerability exploited by authenticated users with contributor-plus roles.
5
What plugin is involved in CVE-2022-38140?
CVE-2022-38140 involves the Squirrly SEO plugin for WordPress, specifically versions 12.1.10 and earlier.