CRITICAL

CVE-2022-0316

CVSS v3

9.8

CRITICAL

EPSS Score

38.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

Technical details

Published
1/23/2023

Frequently asked questions

What is CVE-2022-0316?

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

Is CVE-2022-0316 actively exploited?

Active exploitation of CVE-2022-0316 has not been confirmed. The EPSS score is 38.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0316?

CVE-2022-0316 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-0316 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.