Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19803
HistoryMar 02, 2022 - 12:00 a.m.

WordPress Cost Calculator plugin path traversal vulnerability

2022-03-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
wordpress
cost calculator
path traversal
vulnerability
php
mysql
windows web servers
contributor

EPSS

0.001

Percentile

40.2%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language. The platform supports the hosting of personal blog sites on servers with PHP and MySQL. WordPress Cost Calculator plugin version 1.4 and earlier contains a path traversal vulnerability that stems from the failure of a web system or product to properly filter special elements in a resource or file path. An attacker could exploit this vulnerability to allow users with roles as low as Contributor to perform path traversal on Windows Web servers via layouts published by Cost Calculator.

EPSS

0.001

Percentile

40.2%