CVE Vulnerabilities

CVE-2022-4794

Published: Jan 30, 2023 | Modified: Mar 28, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

Affected Software

NameVendorStart VersionEnd Version
Amazon_affiliate_wordpress_pluginGetaawp*3.12.3 (excluding)

References