Vulnerability Description
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commoninja | Videos Sync Pdf | <= 1.7.4 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/166534/ExploitThird Party AdvisoryVDB Entry
- https://wpscan.com/vulnerability/fe3da8c1-ae21-4b70-b3f5-a7d014aa3815ExploitThird Party Advisory
- https://packetstormsecurity.com/files/166534/ExploitThird Party AdvisoryVDB Entry
- https://wpscan.com/vulnerability/fe3da8c1-ae21-4b70-b3f5-a7d014aa3815ExploitThird Party Advisory
FAQ
What is CVE-2022-1392?
CVE-2022-1392 is a vulnerability with a CVSS score of 7.5 (HIGH). The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
How severe is CVE-2022-1392?
CVE-2022-1392 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1392?
Check the references section above for vendor advisories and patch information. Affected products include: Commoninja Videos Sync Pdf.