← Back to CVE List

CVE-2022-2557

Published: 2022-08-22T15:15Z
Last Modified: 2024-11-21T07:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user > MITRE Terms of Use apply – see LICENSE‑MITRE.txt