CVE Vulnerabilities

CVE-2022-4057

Direct Request ('Forced Browsing')

Published: Jan 02, 2023 | Modified: Apr 10, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugins exported settings and logs.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
AutooptimizeOptimizingmatters*3.1.0 (excluding)

Potential Mitigations

References