.. / CVE-2022-1392

Exploit for WordPress Videos sync PDF <=1.7.4 - Local File Inclusion (CVE-2022-1392)

Description:

WordPress Videos sync PDF 1.7.4 and prior does not validate the p parameter before using it in an include statement, which could lead to local file inclusion.

Nuclei Template

View the template here CVE-2022-1392.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-1392.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://wpscan.com/vulnerability/fe3da8c1-ae21-4b70-b3f5-a7d014aa3815
https://packetstormsecurity.com/files/166534/
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2022-1392