CVE-2022-1390 is a critical vulnerability affecting the Admin Word Count Column WordPress plugin up to version 2.2. It allows unauthenticated attackers to perform arbitrary file reading via a path traversal flaw, potentially leading to Remote Code Execution (RCE) through Phar Deserialization on older PHP versions. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/ExploitDB modules, Nuclei templates exist for Local File Inclusion, and the vulnerability has a very high EPSS score, indicating a significant likelihood of exploitation. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2CPE matchmatch criteria | cpe:2.3:a:admin_word_count_column_project:admin_word_count_column:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.