CVE-2022-4949: AdSanity < 1.8.2 - Authenticated Arbitrary File Upload
The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajaxupload' function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers with Contributor+ level privileges to upload arbitrary files on the affected sites server which makes remote code execution possible.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-4949?
CVE-2022-4949 is a vulnerability in the AdSanity plugin for WordPress that allows authenticated attackers with Contributor+ level privileges to upload arbitrary files.
How does CVE-2022-4949 affect the AdSanity plugin for WordPress?
CVE-2022-4949 affects versions up to and including 1.8.1 of the AdSanity plugin for WordPress.
How severe is CVE-2022-4949?
CVE-2022-4949 has a severity rating of 8.8 (high).
How can I fix the CVE-2022-4949 vulnerability in the AdSanity plugin?
To fix the CVE-2022-4949 vulnerability in the AdSanity plugin, update to version 1.8.2 or later.
Where can I find more information about CVE-2022-4949?
You can find more information about CVE-2022-4949 at the following references: [1] https://blog.nintechnet.com/critical-vulnerability-in-wordpress-adsanity-plugin/ [2] https://www.wordfence.com/threat-intel/vulnerabilities/id/effd72d2-876d-4f8d-b1e4-5ab38eab401b?source=cve [3] http://xenbits.xen.org/xsa/advisory-443.html