ZeroHour

CVE-2022-4298

PoC
CVSS 3.1
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

Vendors
cedcommerce
Products
wholesale market
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.