PT-2022-25289 · WordPress · Xplodedthemes Wpide

Re-Alter

+1

·

Published

2022-09-21

·

Updated

2022-09-23

·

CVE-2022-40217

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XplodedThemes WPide plugin versions <= 2.6
Description The issue is an Authenticated Arbitrary File Edit/Upload vulnerability. This means that an attacker with admin or higher privileges can edit or upload files arbitrarily in the XplodedThemes WPide plugin at WordPress.
Recommendations For XplodedThemes WPide plugin versions <= 2.6, update to a version higher than 2.6 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40217

Affected Products

Xplodedthemes Wpide