Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-4298

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.12
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-4298


Contact Us

Shodan ® - All rights reserved