Unrated severityNVD Advisory· Published Jan 23, 2023· Updated Apr 3, 2025
Multiple themes - Unauthenticated Arbitrary File Upload
CVE-2022-0316
Description
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7cmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.