Woocommerce CSV importer <= 3.3.6 - Arbitrary File Deletion
mediumThe Woocommerce CSV importer plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3.6 via the delete_export_file() function. This allows authenticated attackers to execute code on the server.
- CVSS:
- 6.4
- Affected:
- up to 3.3.6
- Fixed in:
- 3.4.0
- Disclosed:
- Dec 27, 2017