← Back to browse · API

CVE-2022-0316

Severity
CRITICAL
CVSS
9.8
EPSS
0.02084
Risk score
39.93
CISA KEV
No
PoC
No
Published
2023-01-23
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2022-15486, GHSA-J5H9-7HP2-65W5
Products
Unknown:WeStand 0 <2.1, Unknown:aidreform 0 ≤*, Unknown:bolster 0 ≤*, Unknown:club-theme 0 ≤*, Unknown:footysquare 0 ≤*, Unknown:kingclub-theme 0 ≤*, Unknown:soundblast 0 ≤*, Unknown:spikes 0 ≤*, Unknown:spikes-black 0 ≤*, Unknown:statfort 0 ≤*
Sources
euvd EUVD-2022-15486

Description

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

References