Record summary

CVE-2022-1390 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Admin Word Count Column

CVE List2.2 to ≤ 2.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Admin Word Count Column 2.2 - Local File InclusionCVSS 9.8

The plugin does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to further compromise.

Remediation

Update to the latest version of the WordPress Admin Word Count Column plugin (2.2 or higher) to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authorsdaffainfo, Splint3r7
Template tagscvecve2022packetstormwpscanwordpresswp-pluginlfiwpadmin_word_count_column_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:admin_word_count_column_project:admin_word_count_column:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3