← back
CVE-2022-2261CWE-22

WPide < 3.0 - Admin+ Local File Inclusion

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.2%
exploitation probability
1.2%top 36% of all CVEs
observed exploitation
nono source reports it
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.