SMSA Shipping for WooCommerce <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Download

2022-11-22 00:00
WPScanTeam

Strategic Overview

Status
Patched in 1.0.5
Affected Version<= 1.0.4
CVSS6.5Medium
CVECVE-2022-4107
View all SMSA Shipping for WooCommerce vulnerabilities

Vulnerability Overview

The SMSA Shipping for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download due to missing file validation on file download functionality in versions up to, and including, 1.0.4. This makes it possible for subscriber-level attackers with any file download functionality to access and download any arbitrary file on the server, including database configuration files.

Technical Analysis

REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C