Wholesale Market for WooCommerce < 1.0.7 - Unauthenticated Arbitrary File Download
CVE-2022-4106
7.5HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 19 December 2022
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2022-4106?
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Affected Version(s)
Wholesale Market for WooCommerce 0 < 1.0.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.