CVE-2022-45374: WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.4 - Local File Inclusion
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.
Affected Software
2 affected components
YARPP Yet Another Related Posts Plugin<=5.30.4
YARPP Yet Another Related Posts Plugin Wordpress<5.30.5
Remediation
Information
Update to 5.30.5 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:28 AM
Data Sourced
via MITRE·06:28 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45374?
CVE-2022-45374 is classified as a high severity vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2022-45374?
To fix CVE-2022-45374, update YARPP to the latest version beyond 5.30.4.
3
What impact does CVE-2022-45374 have on users?
CVE-2022-45374 allows for improper limitation of pathname, enabling attackers to access restricted files on the server.
4
Which versions of YARPP are affected by CVE-2022-45374?
CVE-2022-45374 affects YARPP versions from n/a through 5.30.4.
5
Is there a way to mitigate CVE-2022-45374 without updating?
While updating is the recommended approach, restricting file access permissions may mitigate some risks associated with CVE-2022-45374.