SMSA Shipping <= 2.3 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The SMSA Shipping (official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can ea...
- CVSS:
- 8.1
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Jan 6, 2026
CVE-2024-49249 on NVD →
SMSA Shipping (official) [smsa-shipping-official] < 2.4
unknown
[en] Path Traversal vulnerability in SMSA Express SMSA Shipping allows Path Traversal.This issue affects SMSA Shipping: from n/a through 2.3.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Jan 7, 2025
CVE-2024-49249 on NVD →
SMSA Shipping (official) [smsa-shipping-official] < 2.4
unknown
[en] The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arb...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Dec 21, 2024
CVE-2024-12066 on NVD →
SMSA Shipping(official) <= 2.3 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrar...
- CVSS:
- 8.8
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Dec 20, 2024
CVE-2024-12066 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database