Woocommerce CSV importer <= 3.3.6 - Arbitrary File Deletion
2017-12-27 00:00
Lenon LeiteStrategic Overview
StatusPatched in 3.4.0
Affected PluginWoocommerce CSV importer
Affected Version
<= 3.3.6CVSS6.4Medium
CVE
N/AVulnerability Overview
The Woocommerce CSV importer plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3.6 via the delete_export_file() function. This allows authenticated attackers to execute code on the server.
Technical Analysis
REMEDIATION: Update to version 3.4.0, or a newer patched version --- IDENTIFIER: CWE-73 (External Control of File Name or Path) The product allows user input to control or influence paths or file names that are used in filesystem operations.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C