plugin

Smsa Shipping For Woocommerce Vulnerabilities

2 known security issues reported for the Smsa Shipping For Woocommerce WordPress plugin. Most recent disclosed Dec 19, 2022.

1 medium

Running Smsa Shipping For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

SMSA Shipping for WooCommerce [smsa-shipping-for-woocommerce] < 1.0.5

unknown

[en] The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Dec 19, 2022

CVE-2022-4107 on NVD →

SMSA Shipping for WooCommerce <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Download

medium

The SMSA Shipping for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download due to missing file validation on file download functionality in versions up to, and including, 1.0.4. This makes it possible for subscriber-level attackers with any file download functionality to access and download any arb...

CVSS:
6.5
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Nov 22, 2022

CVE-2022-4107 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database