The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/f927dbe0-3939-4882-a469-1309ac737ee6 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/f927dbe0-3939-4882-a469-1309ac737ee6 | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2023-01-09 23:15
Updated : 2025-04-09 20:15
NVD link : CVE-2022-3416
Mitre link : CVE-2022-3416
CVE.ORG link : CVE-2022-3416
JSON object : View
Products Affected
                bravenewcode
- wptouch
CWE
                No CWE.
