Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3762
HistoryNov 21, 2022 - 12:00 a.m.

CVE-2022-3762 Booster for WooCommerce - ShopManager+ Arbitrary File Download

2022-11-2100:00:00
WPScan
www.cve.org
2
cve
woocommerce
plugin
arbitrary file download
shopmanager
admin
multisite

EPSS

0.001

Percentile

32.8%

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Booster for WooCommerce",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.6.7"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  },
  {
    "vendor": "Unknown",
    "product": "Booster Plus for WooCommerce",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.6.5"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "Unknown",
    "product": "Booster Elite for WooCommerce",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "1.1.7"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

EPSS

0.001

Percentile

32.8%

Related for CVELIST:CVE-2022-3762