Arbitrary File Deletion in Order Export & Order Import Plugin for WooCommerce
CVE-2024-13922

6.5MEDIUM

What is CVE-2024-13922?

The Order Export & Order Import for WooCommerce plugin for WordPress has a security flaw where insufficient validation of file paths in the admin_log_page() function could allow authenticated users, particularly those with Administrator-level access, to delete arbitrary log files from the server. All versions up to and including 2.6.0 are affected, exposing the system to potential data loss and other security risks as unauthorized file deletions could disrupt operations or expose sensitive information.

Affected Version(s)

Order Export & Order Import for WooCommerce * <= 2.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hay Mizrachi
.