Lucene search

K
cvePatchstackCVE-2022-47595
HistoryMar 14, 2023 - 7:15 a.m.

CVE-2022-47595

2023-03-1407:15:12
CWE-22
Patchstack
web.nvd.nist.gov
28
cve-2022-47595
path traversal
wp go maps
wordpress
security vulnerability

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

29.8%

Improper Limitation of a Pathname to a Restricted Directory (β€˜Path Traversal’) vulnerability in WP Go Maps (formerly WP Google Maps) plugin <=Β 9.0.15 versions.

Affected configurations

Nvd
Vulners
Node
codecabinwp_go_mapsRange≀9.0.15wordpress
VendorProductVersionCPE
codecabinwp_go_maps*cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "wp-google-maps",
    "product": "WP Go Maps (formerly WP Google Maps)",
    "vendor": "WP Go Maps",
    "versions": [
      {
        "changes": [
          {
            "at": "9.0.16",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "9.0.15",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

29.8%

Related for CVE-2022-47595