CVE-2022-4106: Wholesale Market for WooCommerce < 1.0.7 - Unauthenticated Arbitrary File Download
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4106?
CVE-2022-4106 is a vulnerability in the Wholesale Market for WooCommerce WordPress plugin before version 1.0.7 that allows unauthenticated attackers to download arbitrary files from the server.
How severe is CVE-2022-4106?
CVE-2022-4106 has a severity rating of 7.5 out of 10, which is considered high.
What is the affected software for CVE-2022-4106?
The affected software is Cedcommerce Wholesale Market For Woocommerce plugin before version 1.0.7.
How can unauthenticated attackers exploit CVE-2022-4106?
Unauthenticated attackers can exploit CVE-2022-4106 by downloading arbitrary files from the server.
Is there a fix available for CVE-2022-4106?
Yes, a fix for CVE-2022-4106 is available in version 1.0.7 of the Wholesale Market for WooCommerce plugin.