Vulnerability Description
The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Images Optimize And Upload Cf7 Project | Images Optimize And Upload Cf7 | <= 2.1.4 |
References
- https://wpscan.com/vulnerability/2ce4c837-c62c-41ac-95ca-54bb1a6d1eebExploitThird Party Advisory
- https://wpscan.com/vulnerability/2ce4c837-c62c-41ac-95ca-54bb1a6d1eebExploitThird Party Advisory
FAQ
What is CVE-2022-4101?
CVE-2022-4101 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbit...
How severe is CVE-2022-4101?
CVE-2022-4101 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-4101?
Check the references section above for vendor advisories and patch information. Affected products include: Images Optimize And Upload Cf7 Project Images Optimize And Upload Cf7.