CRITICAL · 9.1

CVE-2022-4101

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbit...

Vulnerability Description

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Images Optimize And Upload Cf7 ProjectImages Optimize And Upload Cf7<= 2.1.4

References

FAQ

What is CVE-2022-4101?

CVE-2022-4101 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbit...

How severe is CVE-2022-4101?

CVE-2022-4101 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-4101?

Check the references section above for vendor advisories and patch information. Affected products include: Images Optimize And Upload Cf7 Project Images Optimize And Upload Cf7.