AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-0779

MEDIUM · CVSS 6.5 EPSS 2.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-0779
Severity
MEDIUM
CVSS
6.5
EPSS
2.28%
WordPress

Original NVD Description

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads