PT-2022-14113 · WordPress · Change Uploaded File Permissions

Daniel Ruf

·

Published

2022-06-13

·

Updated

2022-06-21

·

CVE-2022-1788

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Change Uploaded File Permissions WordPress plugin through 4.0.0
Description The issue is due to missing checks, making the plugin vulnerable to CSRF attacks. This vulnerability can be used to change the file and folder permissions of any folder, potentially making specific files like ini files readable for everyone.
Recommendations For versions through 4.0.0, update to a version later than 4.0.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and folders to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1788

Affected Products

Change Uploaded File Permissions