← back
CVE-2022-1392CWE-22

Videos sync PDF <= 1.7.4 - Unauthenticated LFI

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 11%
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues