SMSA Shipping for WooCommerce [smsa-shipping-for-woocommerce] < 1.0.5
unknown
[en] The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Dec 19, 2022
CVE-2022-4107 on NVD →
SMSA Shipping for WooCommerce <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Download
medium
The SMSA Shipping for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download due to missing file validation on file download functionality in versions up to, and including, 1.0.4. This makes it possible for subscriber-level attackers with any file download functionality to access and download any arb...
- CVSS:
- 6.5
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Nov 22, 2022
CVE-2022-4107 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database