CVE-2022-4106
Last modified
CVE-2022-4106 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cedcommerce | Wholesale Market For Woocommerce | < 1.0.7 |
References
- https://wpscan.com/vulnerability/b60a0d3d-148f-4e9b-baee-7332890804edExploit, Third Party Advisory
- https://wpscan.com/vulnerability/b60a0d3d-148f-4e9b-baee-7332890804edExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4106?
How severe is CVE-2022-4106?
How do I fix CVE-2022-4106?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41053Windows Kerberos Denial of Service Vulnerability7.5
- CVE-2022-41054Windows Resilient File System (ReFS) Elevation of Privilege …7.8
- CVE-2022-41055Windows Human Interface Device Information Disclosure Vulner…5.5
- CVE-2022-41056Network Policy Server (NPS) RADIUS Protocol Denial of Servic…7.5
- CVE-2022-41057Windows HTTP.sys Elevation of Privilege Vulnerability7.8
- CVE-2022-41058Windows Network Address Translation (NAT) Denial of Service …7.5
- CVE-2022-41060Microsoft Word Information Disclosure Vulnerability5.5
- CVE-2022-41061Microsoft Word Remote Code Execution Vulnerability7.8
- CVE-2022-41062Microsoft SharePoint Server Remote Code Execution Vulnerabil…8.8
- CVE-2022-41063Microsoft Excel Remote Code Execution Vulnerability7.8
- CVE-2022-41064.NET Framework Information Disclosure Vulnerability5.8
- CVE-2022-41066Microsoft Dynamics Business Central Information Disclosure V…4.4
Are you affected by CVE-2022-4106?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
