Critical severity9.8NVD Advisory· Published Apr 25, 2022· Updated Jun 17, 2026
CVE-2022-1390
CVE-2022-1390
Description
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Admin Word Count Column plugindescription
- Range: <=2.2
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/166476/nvdExploitThird Party AdvisoryVDB Entry
- wpscan.com/vulnerability/6293b319-dc4f-4412-9d56-55744246c990nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.