High severity8.8NVD Advisory· Published Jun 7, 2023· Updated Apr 8, 2026
CVE-2022-4949
CVE-2022-4949
Description
The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers with Contributor+ level privileges to upload arbitrary files on the affected sites server which makes remote code execution possible.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- xenbits.xen.org/xsa/advisory-443.htmlnvdPatchThird Party Advisory
- blog.nintechnet.com/critical-vulnerability-in-wordpress-adsanity-plugin/nvdExploit
- www.wordfence.com/threat-intel/vulnerabilities/id/effd72d2-876d-4f8d-b1e4-5ab38eab401bnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2023/11/09/3nvdMailing List
News mentions
0No linked articles in our index yet.