AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-0403

HIGH · CVSS 8.1 EPSS 1.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-04-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-0403
Severity
HIGH
CVSS
8.1
EPSS
1.23%
WordPress

Original NVD Description

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.