CVE-2024-12861: W2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2sviewlog' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12861?
CVE-2024-12861 is classified as a medium severity vulnerability affecting the W2S – Migrate WooCommerce to Shopify plugin.
How do I fix CVE-2024-12861?
To fix CVE-2024-12861, update the W2S – Migrate WooCommerce to Shopify plugin to version 1.3.0 or higher.
Who is affected by CVE-2024-12861?
CVE-2024-12861 affects authenticated users with Subscriber-level access and above.
What type of vulnerability is CVE-2024-12861?
CVE-2024-12861 is an Arbitrary File Read vulnerability.
Which versions of the W2S plugin are vulnerable to CVE-2024-12861?
All versions of the W2S – Migrate WooCommerce to Shopify plugin up to and including version 1.2.1 are vulnerable to CVE-2024-12861.