PoC Index

CVE-2022-3921

CRITICAL 9.8EPSS 21.2%

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
21.20% chance of exploitation in the next 30 days, 97th percentile
Published
2022-12-12
Updated
2025-04-22

Proof-of-concept exploits (1)

References

Related