The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-01-23 07:15
Updated : 2023-01-31 10:30
NVD link : CVE-2022-0316
Mitre link : CVE-2022-0316
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
chimpgroup
- westand
- bolster
- spikes
spikes-black_project
- spikes-black
pixfill
- kings_club
club-theme_project
- club-theme
aidreform_project
- aidreform
footysquare_project
- footysquare
soundblast_project
- soundblast
statfort_project
- statfort