Amministrazione Aperta [amministrazione-aperta] < 3.8
unknown
[en] The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed d...
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- May 16, 2022
CVE-2022-1560 on NVD →
Amministrazione Aperta <= 3.7.3 - Admin+ Local File Inclusion
medium
The Amministrazione Aperta WordPress plugin through 3.7.3 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed dir...
- CVSS:
- 5.4
- Affected:
- up to 3.7.3
- Fixed in:
- 3.8
- Disclosed:
- Mar 23, 2022
CVE-2022-1560 on NVD →
Amministrazione Aperta [amministrazione-aperta] <= 3.7.3
unknown
Local File Inclusion (LFI) vulnerability discovered by Hassan Khan Yusufzai (Splint3r7) in WordPress Amministrazione Aperta plugin (versions <= 3.7.3).
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.3
- Disclosed:
- Mar 23, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database