Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2943
HistorySep 06, 2022 - 6:15 p.m.

Input validation

2022-09-0618:15:00
PRIOn knowledge base
www.prio-n.com
3
wordpress
infinite scroll
plugin vulnerability
arbitrary file reading
path validation
authenticated attackers
administrative privileges
sensitive content
nvd

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.7%

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.

CPENameOperatorVersion
ajax_load_morelt5.5.4

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.7%

Related for PRION:CVE-2022-2943