CVE Database
/

CVE-2022-1390

Back to search

CVE-2022-1390

Published: Apr 25, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

VendorProductVersions

Unknown

Admin Word Count Column

affected
2.2 - <= 2.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now