Wholesale Market for WooCommerce < 2.0.0 - Authenticated (Administrator+) Arbitrary Log File Download
Strategic Overview
< 2.0.0CVE-2022-4109Vulnerability Overview
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This makes it possible for unauthenticated attackers to download log files from the vulnerable service's server even if they belong to another site.
Technical Analysis
REMEDIATION: Update to version 2.0.0, or a newer patched version --- IDENTIFIER: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C