AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-3899

HIGH · CVSS 8.1 EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-01-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects WordPress.

CVE
CVE-2022-3899
Severity
HIGH
CVSS
8.1
EPSS
0.40%
WordPress

Original NVD Description

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.

Related CVEs

Other vulnerabilities affecting the same vendor(s)