CVE-2022-29446
Status: Analyzed
Last modified:
26-05-2022
Published:
19-05-2022
7.2
SUMMARY CVE-2022-29446
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
Access CVSS3 CVE-2022-29446
Attack Complexity | Attack Vector | Privileges Required | Scope | User Interaction |
---|---|---|---|---|
LOW | NETWORK | HIGH | UNCHANGED | NONE |
Impact CVSS3 CVE-2022-29446
Confidentiality | Integrity | Availability |
---|---|---|
HIGH | HIGH | HIGH |
Details CVE-2022-29446
EPSS | 0.00099 |
---|---|
EPSS % | 0.41864 |
References | |
CWE | CWE-552 |
CAPEC |
|
Vulnerable Configurations |
|
CVSS3 Source | nvd@nist.gov |
CVSS3 Type | Primary |
CVSS3 Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |