Record summary

CVE-2022-1392 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Videos sync PDF

CVE List1.7.4 to ≤ 1.7.4affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Videos sync PDF <=1.7.4 - Local File InclusionCVSS 7.5

WordPress Videos sync PDF 1.7.4 and prior does not validate the p parameter before using it in an include statement, which could lead to local file inclusion.

Impact

Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially leading to further compromise of the system.

Remediation

Upgrade to the latest version of WordPress Videos sync PDF plugin (>=1.7.5) or apply the vendor-provided patch to mitigate the vulnerability.

WeaknessesCWE-22
AuthorsVeshraj
Template tagscvecve2022lfiwp-pluginunauthwpscanpacketstormwpwordpresscommoninjavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:commoninja:videos_sync_pdf:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3