WordPress Plugin admin-word-count-column 2.2 Local File Read
CVE-2022-50953
6.9MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 8 June 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2022-50953?
WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal sequences and null bytes to bypass file restrictions and read sensitive files like system configuration.
Affected Version(s)
admin-word-count-column 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Hassan Khan Yusufzai - Splint3r7