CVE-2022-0316
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.
Published:Jan 23, 2023
Last Modified:Apr 3, 2025
EPS:Jan 23, 2023
EPSS Score:0.23032
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Aidreform Project
Product
Aidreform
Aidreform Project
Aidreform
Vendor
Chimpgroup
Product
Bolster
Chimpgroup
Bolster
Vendor
Chimpgroup
Product
Spikes
Chimpgroup
Spikes
Vendor
Chimpgroup
Product
Westand
Chimpgroup
Westand
Vendor
Club-theme Project
Product
Club-theme
Club-theme Project
Club-theme
Vendor
Footysquare Project
Product
Footysquare
Footysquare Project
Footysquare
Vendor
Pixfill
Product
Kings Club
Pixfill
Kings Club
Vendor
Soundblast Project
Product
Soundblast
Soundblast Project
Soundblast
Vendor
Spikes-black Project
Product
Spikes-black
Spikes-black Project
Spikes-black
Vendor
Statfort Project
Product
Statfort
Statfort Project
Statfort
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
