CVE-2024-13922: Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the adminlogpage() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13922?
CVE-2024-13922 has a medium severity rating due to its potential for arbitrary file deletion.
How do I fix CVE-2024-13922?
To fix CVE-2024-13922, update the WooCommerce Order Export & Order Import plugin to version 2.6.1 or later.
Who is affected by CVE-2024-13922?
CVE-2024-13922 affects all versions of the WooCommerce Order Export & Order Import plugin up to and including version 2.6.0.
What types of attacks can exploit CVE-2024-13922?
CVE-2024-13922 can be exploited by authenticated attackers to delete arbitrary files on the server.
Are there any known exploits for CVE-2024-13922?
As of the current date, there are no public exploits reported for CVE-2024-13922.