vulnerability

WordPress Plugin: wholesale-market-for-woocommerce: CVE-2022-4109: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Severity
3
CVSS
(AV:N/AC:L/Au:M/C:P/I:N/A:N)
Published
Dec 12, 2022
Added
May 15, 2025
Modified
May 15, 2025

Description

The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This makes it possible for unauthenticated attackers to download log files from the vulnerable service's server even if they belong to another site.

Solution

wholesale-market-for-woocommerce-plugin-cve-2022-4109
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.