S2W – Import Shopify to WooCommerce <= 1.1.12 - Authenticated (Admin+) Local File Inclusion
highThe S2W – Import Shopify to WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.12, via insufficient restrictions in the 'generate_log_ajax' function. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the exe...
- CVSS:
- 7.2
- Affected:
- up to 1.1.12
- Fixed in:
- 1.1.13
- Disclosed:
- Nov 10, 2022