The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-01-02T21:49:31.099Z

Updated: 2023-01-10T09:08:51.783Z

Reserved: 2022-11-21T22:52:26.396Z


Link: CVE-2022-4109

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-02T22:15:16.077

Modified: 2023-11-07T03:56:57.037


Link: CVE-2022-4109

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.