nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50956 CVE-2022-50956
MEDIUM
WordPress Plugin amministrazione-aperta 3.7.3 Local File Read
Record summary
CVE-2022-50956 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
amministrazione-apertaBrowse amministrazione-aperta / amministrazione-aperta | CVE List | 3.7.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - UnauthenticatedExploitDB exploitby Hassan Khan YusufzaiNot analyzed1 file
References
4Official Product Homepageproduct
https://wordpress.org/plugins/amministrazione-aperta ExploitDB-50838exploit
https://www.exploit-db.com/exploits/50838 VulnCheck Advisory: WordPress Plugin amministrazione-aperta 3.7.3 Local File ReadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-amministrazione-aperta-local-file-read