2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-0316" ,
"sourceIdentifier" : "contact@wpscan.com" ,
"published" : "2023-01-23T15:15:13.703" ,
2023-11-07 21:03:21 +00:00
"lastModified" : "2023-11-07T03:41:12.380" ,
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:aidreform_project:aidreform:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "349B3C5A-3C95-4C80-9C09-DCFE002CB048"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:chimpgroup:bolster:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "CD32D146-AE32-4F24-BB13-034D0BCEE102"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:chimpgroup:spikes:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "692D91D4-FE19-4C7B-A0C2-8ADFF4EF3DA0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:chimpgroup:westand:*:*:*:*:*:wordpress:*:*" ,
"versionEndExcluding" : "2.1" ,
"matchCriteriaId" : "82C6F1C1-034D-41D4-B1B0-E97E860F60BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:club-theme_project:club-theme:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "62CF701B-A5BF-4A80-A1DA-D7BD3DCC62B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:footysquare_project:footysquare:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "E8492E39-28B9-4291-86A9-CA7C883EA483"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:pixfill:kings_club:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "241E870E-DBF9-442A-A2E8-335375EB3995"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:soundblast_project:soundblast:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "8E8B3706-CC83-422D-8F3E-35E454B25C9B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:spikes-black_project:spikes-black:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "F95938E5-CC29-453F-8C22-0AF971A7CE76"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:statfort_project:statfort:-:*:*:*:*:wordpress:*:*" ,
"matchCriteriaId" : "B9E2332D-410F-4765-8C6E-6A0FB07795CE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c" ,
"source" : "contact@wpscan.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
}
]
}