Kiwiz - Certification de facturation - Woocommerce <= 2.1.3 - Unauthenticated Arbitrary File Download
highThe Kiwiz - Certification de facturation - Woocommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads in versions up to, and including, 2.1.3. This is due to improper restrictions on the file path being supplied for a file download. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.5
- Affected:
- up to 2.1.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 19, 2023