Wholesale Market for WooCommerce < 2.0.0 - Authenticated (Administrator+) Arbitrary Log File Download
medium
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This makes it possible for unauthenticated attackers to download log files from the vulnerab...
- CVSS:
- 4.1
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Dec 12, 2022
CVE-2022-4109 on NVD →
Wholesale Market for WooCommerce <= 2.0.0 & Wholesale Market <= 2.2.1 - Cross-Site Request Forgery
medium
Multiple plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on the 'wholesale_market' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Dec 8, 2022
CVE-2022-4363 on NVD →
Wholesale Market for WooCommerce <= 1.0.6 - Unauthenticated Arbitrary File Download
high
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capability checks and user input validation during the system path generation process in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to download arbitrary file...
- CVSS:
- 7.5
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Nov 28, 2022
CVE-2022-4106 on NVD →
Wholesale Market for WooCommerce <= 1.0.7 - Authenticated (Administrator+) Arbitrary File Download
medium
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing user input validation during the system path generation process in versions up to, and including, 1.0.7. This makes it possible for authenticated attackers with administrator-level privileges to download ar...
- CVSS:
- 4.9
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Nov 28, 2022
CVE-2022-4108 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database