S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1392 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in The Videos sync PDF plugin for WordPress affects v. through 1.7.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1392
7.5
CVSS

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Videos sync PDF
1.7.4
Updated Aug 22, 2026View on NVD →
Detail

The Videos sync PDF WordPress plugin is a popular tool designed to facilitate the process of embedding video content into PDF files. This plugin is widely used by website owners, digital marketers, and publishers who aim to create engaging and interactive content for their audiences. With the Videos sync PDF plugin, users can integrate video content from various platforms such as YouTube, Vimeo, and Wistia, into their PDFs seamlessly. This tool provides an efficient and easy way for content creators to attract more viewers and improve engagement rates.

However, the recent discovery of a vulnerability identified as CVE-2022-1392 in the Videos sync PDF WordPress plugin version 1.7.4 has raised concerns among web administrators and security professionals. This vulnerability arises from the lack of proper input validation in the "p" parameter used in the plugin's include statement. An attacker can exploit this vulnerability by manipulating the "p" parameter to execute arbitrary code in the system's context, leading to Local File Inclusion (LFI) issues.

When exploited, the CVE-2022-1392 vulnerability can compromise the entire website and even the server. An attacker can gain access to sensitive data and files stored on the server, including user credentials, personal information, and confidential business data. This type of attack can lead to a loss of trust among customers and even legal consequences for the website owner. Therefore, it is crucial to take measures to protect website owners and users from this security threat.

In conclusion, it's essential to stay up-to-date with the latest security news and vulnerabilities that can threaten your digital assets. By using pro features available on the s4e.io platform, administrators will receive alerts about potential threats and gain insights into how to secure their digital assets. With this platform, website owners and administrators can ensure the safety of their website, users, and sensitive data.

 

REFERENCES

Solution Advice

To protect websites from the CVE-2022-1392 vulnerability, administrators can take the following precautions:

  • Update the Videos sync PDF WordPress plugin to the latest patched version that resolves the vulnerability
  • Install a Web Application Firewall (WAF) to block access to malicious requests
  • Implement proper input validation and sanitization techniques to prevent code injection attacks
  • Monitor server logs and check for any suspicious activities or requests
  • Use security scanners to identify any other vulnerabilities that may exist on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.