CyberRota Analysis
AI analysis pending.
CVE
CVE-2022-0779
Severity
MEDIUM
CVSS
6.5
EPSS
2.28%
WordPress
Original NVD Description
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads