The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c - Exploit, Third Party Advisory |
07 Nov 2023, 03:41
Type | Values Removed | Values Added |
---|---|---|
CWE |
Information
Published : 2023-01-23 15:15
Updated : 2025-04-03 20:15
NVD link : CVE-2022-0316
Mitre link : CVE-2022-0316
CVE.ORG link : CVE-2022-0316
JSON object : View
Products Affected
spikes-black_project
- spikes-black
footysquare_project
- footysquare
statfort_project
- statfort
chimpgroup
- westand
- bolster
- spikes
club-theme_project
- club-theme
soundblast_project
- soundblast
pixfill
- kings_club
aidreform_project
- aidreform
CWE
No CWE.