peter bassill · operator
$ cve CVE-2022-4101 JSON

CVE-2022-4101

9.1
CRITICAL · CVSS 3.1 · EPSS 29.4% (pctl 98)

Patch early

EPSS 29.4% — above the 10% action threshold.

Description

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS29.37% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploitnone known
Published2023-01-16
Last modified2026-06-17

Affected (1)

VendorProduct
images optimize and upload cf7 projectimages optimize and upload cf7

References

→ the Explorer  ·  watch your stack  ·  NVD