CVE Database
/

CVE-2022-2557

Back to search

CVE-2022-2557

Published: Aug 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

VendorProductVersions

Unknown

Team – WordPress Team Members Showcase Plugin

affected
4.1.2 - < 4.1.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now