Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-4794

Description

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

POC

Reference

- https://wpscan.com/vulnerability/feb4580d-df15-45c8-b59e-ad406e4b064c

Github

- https://github.com/20142995/nuclei-templates