Arbitrary File Deletion Vulnerability in SMSA Shipping Plugin for WordPress
CVE-2024-12066
8.8HIGH
What is CVE-2024-12066?
CVE-2024-12066 identifies a significant security vulnerability in the SMSA Shipping plugin for WordPress, which is present in all versions up to and including 2.2. The issue arises from inadequate validation of file paths within the smsa_delete_label() function, permitting authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server. This flaw poses a severe risk, as the deletion of critical files—such as wp-config.php—could enable the attackers to execute arbitrary code remotely, compromising the entire WordPress installation.
Affected Version(s)
SMSA Shipping(official) * <= 2.2