CVE-2022-4109
Wholesale Market for WooCommerce < 2.0.0 - Admin+ Arbitrary Log Download
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)
El complemento Wholesale Market for WooCommerce de WordPress anterior a 2.0.0 no valida la entrada del usuario contra ataques de recorrido de ruta, lo que permite a usuarios con privilegios elevados, como el administrador, descargar registros arbitrarios del servidor incluso cuando no deberĂan poder hacerlo (por ejemplo, en sitios mĂșltiples).
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This makes it possible for unauthenticated attackers to download log files from the vulnerable service's server even if they belong to another site.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-21 CVE Reserved
- 2022-12-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/51e023de-189d-4557-9655-23f7ba58b670 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cedcommerce Search vendor "Cedcommerce" | Wholesale Market For Woocommerce Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" | < 2.0.0 Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" and version " < 2.0.0" | wordpress |
Affected
|