Beveiligingsadvies

CVE-2023-4216

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-09-04 11:27:03
Laatst bijgewerkt 2025-04-23 16:17:49
Toegewezen door WPScan
CVSS-score 2.7
Status PUBLISHED

Beschrijving

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.