← Back to browse · API

CVE-2022-4774

Severity
CRITICAL
CVSS
9.8
EPSS
0.01785
Risk score
39.82
CISA KEV
No
PoC
No
Published
2023-05-15
Modified
2025-01-24
First seen
2026-08-07
Aliases
EUVD-2022-52070, GHSA-5267-X3G9-G6X7
Products
Unknown:Bit Form 0 <1.9
Sources
euvd EUVD-2022-52070

Description

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

References