CVE-2022-4748EPSS p54.0%
CVE-2022-4748CVE-2022-4748
flatpress / flatpress
Description
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5d5c7f6d8f072d14926fc2c3a97cdd763802f170. It is recommended to apply a patch to fix this issue. The identifier VDB-216861 was assigned to this vulnerability.
Scoring
| CVSS | 5.5 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.87% probability of exploitation · percentile 54.0% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |