← Back to browse · API

CVE-2022-4101

Severity
CRITICAL
CVSS
9.1
EPSS
0.29369
Risk score
46.68
CISA KEV
No
PoC
No
Published
2023-01-16
Modified
2025-04-04
First seen
2026-08-07
Aliases
EUVD-2022-51471, GHSA-WVP8-6WRP-JWW8
Products
Unknown:Images Optimize and Upload CF7 0 ≤2.1.4
Sources
euvd EUVD-2022-51471

Description

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

References