Junglewise Threat Intelligence

CVE-2022-50953: WordPress Admin Word Count Column local file read in download-csv.php

CVE-2022-50953 · Severity: medium · CVSS 6.2 · Published 2026-06-08

Executive brief

The Admin Word Count Column plugin for WordPress, which adds word count tracking to the administrative dashboard, contains a security flaw that allows unauthorized users to access private files on the web server. By sending a specially crafted web request, an attacker can bypass security restrictions to download sensitive information such as system configuration files or database credentials. This plugin was permanently closed and removed from the WordPress directory in March 2022 due to this security issue.

Technical details

A local file read vulnerability exists in the 'download-csv.php' file of the Admin Word Count Column plugin version 2.2. The issue stems from insufficient validation of the 'path' GET parameter, which is passed directly to the PHP readfile() function. An unauthenticated attacker can use directory traversal sequences (../) combined with a null byte injection (%00) to terminate the file path and bypass the appended '.csv' extension. This allows for the retrieval of arbitrary files from the server, such as /etc/passwd or wp-config.php. Note that null byte injection is generally effective only on PHP versions 5.3.4 and earlier. The plugin has been withdrawn from the WordPress repository and users are advised to uninstall it.

Affected products

  • brooks24 Admin Word Count Column 2.2

Timeline

  • 2022-03-27: disclosed: Initial discovery by Hassan Khan Yusufzai
  • 2022-03-29: other: Plugin closed and removed from WordPress.org repository due to security issue
  • 2022-03-30: other: Exploit code published on Exploit-DB
  • 2026-06-08: advisory: CVE-2022-50953 published in NVD

References