CVE · High

CVE-2022-4794 — AAWP [aawp] < 3.12.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4794 AAWP [aawp] < 3.12.3 Authorization Bypass Through User-Controlled Key High 7.5 < 3.12.3 3.12.3 2023-01-04

CVE-2022-4794

The AAWP plugin for WordPress versions 3.12.2 and earlier contains a reflected file download vulnerability in its image proxy functionality. This flaw allows unauthenticated attackers to exploit the plugin's trust of certain domains to cause the loading of malicious files from outside sources. The vulnerability was remedied in version 3.12.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.