CVE-2022-0316 is a critical vulnerability affecting several WordPress themes from ChimpStudio and PixFill, including WeStand, footysquare, aidreform, and others. The flaw lies in the lang_upload.php file, which lacks proper authorization and upload validation. This allows any unauthenticated attacker to upload arbitrary files to the web server, leading to a CVSS score of 9.8 (Critical). The attack vector is network-based with low complexity, enabling full compromise of confidentiality, integrity, and availability. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:aidreform_project:aidreform:-:*:*:*:*:wordpress:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:chimpgroup:bolster:-:*:*:*:*:wordpress:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:chimpgroup:spikes:-:*:*:*:*:wordpress:*:* | ||
< 2.1CPE matchmatch criteria | cpe:2.3:a:chimpgroup:westand:*:*:*:*:*:wordpress:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:club-theme_project:club-theme:-:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.