CVE Database /
CVE-2022-4794
CVE · High
CVE-2022-4794 — AAWP [aawp] < 3.12.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4794
|
AAWP [aawp] < 3.12.3 |
Authorization Bypass Through User-Controlled Key |
High
7.5
|
< 3.12.3
|
3.12.3 |
2023-01-04 |
—
|
CVE-2022-4794
The AAWP plugin for WordPress versions 3.12.2 and earlier contains a reflected file download vulnerability in its image proxy functionality. This flaw allows unauthenticated attackers to exploit the plugin's trust of certain domains to cause the loading of malicious files from outside sources. The vulnerability was remedied in version 3.12.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings