CVE-2022-1390
Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 19, 2022
- Published Date
- April 25, 2022
- Last Updated
- August 03, 2024
- Vendor
- Unknown
- Product
- Admin Word Count Column
- Description
- The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique
- Tags
- Score
- 91.00% (Percentile: 99.61%) as of 2025-05-31
- Exploited in the Wild
- Yes (added 2025-05-10 00:00:00 UTC) Source
wordpress
php
nuclei_scanner
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Score
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
The Shadowserver (via CIRCL) | 2025-05-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1390.yaml | 2025-04-26 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Added to KEVIntel