AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-1788

MEDIUM · CVSS 6.5 EPSS 0.74%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-1788
Severity
MEDIUM
CVSS
6.5
EPSS
0.74%
WordPress

Original NVD Description

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.