The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
Advisories
Source ID Title
EUVD EUVD EUVD-2022-34811 The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T00:39:08.000Z

Reserved: 2022-07-27T00:00:00

Link: CVE-2022-2557

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-22T15:15:15.483

Modified: 2024-11-21T07:01:14.797

Link: CVE-2022-2557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.