CVE-2024-13920: Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the downloadfile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13920?
CVE-2024-13920 has a high severity rating due to the potential for authenticated attackers to exploit directory traversal vulnerabilities.
How do I fix CVE-2024-13920?
To fix CVE-2024-13920, update the Order Export & Order Import for WooCommerce plugin to version 2.6.1 or later, which addresses this vulnerability.
Who is affected by CVE-2024-13920?
All installations of the Order Export & Order Import for WooCommerce plugin up to and including version 2.6.0 are affected by CVE-2024-13920.
What is directory traversal in the context of CVE-2024-13920?
Directory traversal in CVE-2024-13920 allows authenticated users with administrator privileges to access restricted files on the server.
Can attackers exploit CVE-2024-13920 without authentication?
No, CVE-2024-13920 requires authentication with administrator-level access for an attacker to exploit the vulnerability.