The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)
Metrics
Affected Vendors & Products
References
History
Mon, 14 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2022-12-19T13:41:44.715Z
Updated: 2025-04-14T18:13:40.570Z
Reserved: 2022-11-21T22:51:52.571Z
Link: CVE-2022-4108

Updated: 2024-08-03T01:27:54.475Z

Status : Modified
Published: 2022-12-19T14:15:12.347
Modified: 2025-04-14T19:15:34.140
Link: CVE-2022-4108

No data.