← Back to CVE List

CVE-2022-0316

Published: 2023-01-23T15:15Z
Last Modified: 2025-04-03T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt