Security Advisory

CVE-2022-0779

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-06 08:50:49
Last updated 2024-08-02 23:40:03
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads