Arbitrary File Deletion Vulnerability in SMSA Shipping Plugin for WordPress
CVE-2024-12066
What is CVE-2024-12066?
CVE-2024-12066 identifies a significant security vulnerability in the SMSA Shipping plugin for WordPress, which is present in all versions up to and including 2.2. The issue arises from inadequate validation of file paths within the smsa_delete_label() function, permitting authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server. This flaw poses a severe risk, as the deletion of critical files—such as wp-config.php—could enable the attackers to execute arbitrary code remotely, compromising the entire WordPress installation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SMSA Shipping(official) * <= 2.2
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved