Vulnerability Details CVE-2022-0499
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2022-0499
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.21
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.22
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.23
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.24
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.25
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.30
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.30.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.31
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.32
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.33
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.34
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.35
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.36
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.37
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.37.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.37.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.37.3
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.38
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.39
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.40
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.40.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.40.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.41
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.41.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.41.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.42
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.42.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.42.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.42.3
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.42.4
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.3
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.4
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.5
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.43.6
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.44
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.44.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.1
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.10
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.11
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.12
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.13
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.14
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.15
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.16
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.17
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.18
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.19
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.2
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.20
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.21
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.22
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.3
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.4
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.5
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.6
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.7
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.8
-
cpe:2.3:a:sermon_browser_project:sermon_browser:0.45.9