Fiche vulnérabilité
CVE-2022-4106 : faille élevée Unknown Wholesale Market for WooCommerce (CVSS 7.5)
Description
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 déc. 2022
- Dernière mise à jour
- 14 avr. 2025
Produits concernés
- Unknown Wholesale Market for WooCommerce