CVE-2022-2184

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/08/2022
Last modified:
05/08/2022

Description

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpwhitesecurity:captcha_4wp:*:*:*:*:*:wordpress:*:* 7.1.0 (excluding)