SMSA Shipping for WooCommerce <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Download
2022-11-22 00:00
WPScanTeamStrategic Overview
StatusPatched in 1.0.5
Affected PluginSMSA Shipping for WooCommerce
Affected Version
<= 1.0.4CVSS6.5Medium
CVE
CVE-2022-4107Vulnerability Overview
The SMSA Shipping for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download due to missing file validation on file download functionality in versions up to, and including, 1.0.4. This makes it possible for subscriber-level attackers with any file download functionality to access and download any arbitrary file on the server, including database configuration files.
Technical Analysis
REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C