peter bassill · operator
$ cve CVE-2022-1103 JSON

CVE-2022-1103 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS15.55% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2022-05-16
Last modified2026-06-17

Affected (1)

VendorProduct
advanced uploader projectadvanced uploader

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD