S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0679 Scanner

CVE-2022-0679 scanner - Local File Inclusion vulnerability in Narnoo Distributor plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0679
9.8
CVSS

The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Narnoo Distributor
2.5.1
Updated Aug 22, 2026View on NVD →
Detail

The Narnoo Distributor WordPress plugin is a tool designed for entrepreneurs and travel agencies seeking to add travel services to their website. By implementing this plugin, website developers can gain access to a range of travel content, such as videos and images, as well as make bookings for tours and transportation.

Despite its inherent usefulness, the Narnoo Distributor WordPress plugin also has a significant security flaw that has been identified as CVE-2022-0679. This vulnerability causes an unvalidated and unsanitized 'lib_path' parameter to be used in a call to require(), resulting in a potential disclosure of arbitrary files. Ultimately, the content of the file can be displayed in response to the JSON data, which poses a significant risk to website security.

This vulnerability can lead to a range of nefarious activities, including arbitrary file disclosure and, potentially, remote code execution (RCE). The potential impact of such attacks can be severe, especially if the underlying system is improperly configured. As a result, it is essential to address this vulnerability as soon as possible.

Thanks to cutting-edge security features, the s4e.io platform enables users to receive timely notifications regarding potential vulnerabilities and any updates or patches needed to combat them. By emphasizing this point, business owners, web developers, and various IT professionals can quickly and conveniently stay on top of their digital assets' safety.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website developers and administrators should take the following precautions:

  • Install security patches and updates promptly
  • Keep Website plugins up-to-date in a timely fashion
  • Limit access to the 'narnoo_distributor_lib_request' AJAX action to authenticated users only
  • Implement stricter input validation and sanitization to prevent unsanitized or unvalidated user inputs that could be dangerous
  • Employ the services of a knowledgeable security expert to perform an in-depth analysis of your website's security posture.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0679 scanner - Local File Inclusion vulnerability in Narnoo Distributor plugin for Wordpress | S4E