CVE-2022-4108
Wholesale Market for WooCommerce < 1.0.8 - Admin+ Arbitrary File Download
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)
El complemento de WordPress Wholesale Market para WooCommerce anterior a 1.0.8 no valida la entrada del usuario utilizada para generar la ruta del sistema, lo que permite a usuarios con privilegios elevados, como el administrador, descargar archivos arbitrarios desde el servidor incluso cuando no deberĂan poder hacerlo (por ejemplo, en sitios mĂșltiples).
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing user input validation during the system path generation process in versions up to, and including, 1.0.7. This makes it possible for authenticated attackers with administrator-level privileges to download arbitrary files on the affected site's server, including database configuration files from other sites.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-21 CVE Reserved
- 2022-11-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/9d1770df-91f0-41e3-af0d-522ae4e62470 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cedcommerce Search vendor "Cedcommerce" | Wholesale Market For Woocommerce Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" | < 1.0.8 Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" and version " < 1.0.8" | wordpress |
Affected
|