plugin

Wholesale Market For Woocommerce Vulnerabilities

4 known security issues reported for the Wholesale Market For Woocommerce WordPress plugin. Most recent disclosed Dec 12, 2022.

1 high 3 medium

Running Wholesale Market For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Wholesale Market for WooCommerce < 2.0.0 - Authenticated (Administrator+) Arbitrary Log File Download

medium

The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This makes it possible for unauthenticated attackers to download log files from the vulnerab...

CVSS:
4.1
Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Dec 12, 2022

CVE-2022-4109 on NVD →

Wholesale Market for WooCommerce <= 2.0.0 & Wholesale Market <= 2.2.1 - Cross-Site Request Forgery

medium

Multiple plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on the 'wholesale_market' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site ad...

CVSS:
4.3
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Dec 8, 2022

CVE-2022-4363 on NVD →

Wholesale Market for WooCommerce <= 1.0.6 - Unauthenticated Arbitrary File Download

high

The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capability checks and user input validation during the system path generation process in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to download arbitrary file...

CVSS:
7.5
Affected:
up to 1.0.6
Fixed in:
1.0.7
Disclosed:
Nov 28, 2022

CVE-2022-4106 on NVD →

Wholesale Market for WooCommerce <= 1.0.7 - Authenticated (Administrator+) Arbitrary File Download

medium

The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing user input validation during the system path generation process in versions up to, and including, 1.0.7. This makes it possible for authenticated attackers with administrator-level privileges to download ar...

CVSS:
4.9
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Nov 28, 2022

CVE-2022-4108 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database