← All CVEs

CVE-2022-3416

high · 7.2

The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

7.2
CVSS
17.3%
EPSS (exploit prob.)
97th
EPSS percentile
2023-01-09
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
bravenewcodewptouch< 4.3.45

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-3416