CVE Vulnerabilities

CVE-2022-4794

Published: Jan 30, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

Affected Software

Name Vendor Start Version End Version
Amazon_affiliate_wordpress_plugin Getaawp * 3.12.3 (excluding)

References