PT-2022-24233 · Squirrly · Squirrly Seo Plugin

Rafie Muhammad

+1

·

Published

2022-11-28

·

Updated

2022-12-01

·

CVE-2022-38140

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEO Plugin by Squirrly SEO plugin versions 12.1.10 and earlier
Description The issue concerns an arbitrary file upload vulnerability in the SEO Plugin by Squirrly SEO plugin, affecting WordPress. This vulnerability can be exploited by contributors and higher-privileged users.
Recommendations For versions 12.1.10 and earlier, update to a version later than 12.1.10 to resolve the issue.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-38140

Affected Products

Squirrly Seo Plugin