2 results (0.005 seconds)

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2024 — The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. El complemento Product Input Fields for WooCommerce para WordPress es vulnerable a Director... • https://plugins.trac.wordpress.org/changeset/3195423/product-input-fields-for-woocommerce/trunk?contextall=1&old=3173573&old_path=%2Fproduct-input-fields-for-woocommerce%2Ftrunk • CWE-35: Path Traversal: '.../ •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 2

03 Aug 2020 — The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service. • https://blog.nintechnet.com/high-severity-vulnerability-fixed-in-product-input-fields-for-woocommerce • CWE-285: Improper Authorization CWE-862: Missing Authorization •