Lucene search

K
cveWPScanCVE-2022-4346
HistoryJan 23, 2023 - 3:15 p.m.

CVE-2022-4346

2023-01-2315:15:14
WPScan
web.nvd.nist.gov
83
cve-2022-4346
all-in-one security
aios
wordpress
plugin
security vulnerability
leaked settings
email address
nvd

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

40.7%

The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

Affected configurations

Nvd
Vulners
Node
updraftplusall-in-one_securityRange<5.1.3wordpress
VendorProductVersionCPE
updraftplusall-in-one_security*cpe:2.3:a:updraftplus:all-in-one_security:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "All-In-One Security (AIOS)",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.1.3"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

40.7%