Vulnerability Description
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp-Dbmanager Project | Wp-Dbmanager | < 2.80.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/1c8c5861-ce87-4813-9e26-470d63c1903aExploitThird Party Advisory
- https://wpscan.com/vulnerability/1c8c5861-ce87-4813-9e26-470d63c1903aExploitThird Party Advisory
FAQ
What is CVE-2022-2354?
CVE-2022-2354 is a vulnerability with a CVSS score of 7.2 (HIGH). The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
How severe is CVE-2022-2354?
CVE-2022-2354 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2354?
Check the references section above for vendor advisories and patch information. Affected products include: Wp-Dbmanager Project Wp-Dbmanager.