CVE-2022-50953: BROOKS24 Admin-Word-Count-Column

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal sequences and null bytes to bypass file restrictions and read sensitive files like system configuration.

Affected products

  • BROOKS24 Admin-Word-Count-Column: version 2.2 only

Published 2026-06-08. Last modified 2026-07-23.