CVE-2022-1390
9.8
CRITICAL · CVSS 3.1 · EPSS 21.9% (pctl 98)
Patch early
EPSS 21.9% — above the 10% action threshold.
Description
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 21.88% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-04-25 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| admin word count column project | admin word count column |
References
→ the Explorer · watch your stack · NVD