Arbitrary File Deletion Vulnerability in SMSA Shipping Plugin for WordPress
CVE-2024-12066

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 December 2024

Summary

CVE-2024-12066 identifies a significant security vulnerability in the SMSA Shipping plugin for WordPress, which is present in all versions up to and including 2.2. The issue arises from inadequate validation of file paths within the smsa_delete_label() function, permitting authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server. This flaw poses a severe risk, as the deletion of critical files—such as wp-config.php—could enable the attackers to execute arbitrary code remotely, compromising the entire WordPress installation.

Affected Version(s)

SMSA Shipping(official) * <= 2.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Sans-Souci
.