CVE-2022-4106

CVE-2022-4106: Wholesale Market for WooCommerce < 1.0.7 - Unauthenticated Arbitrary File Download

Vendor Unknown
Product Wholesale Market for WooCommerce
Published December 19, 2022
Last update April 14, 2025

CVSS base score

What the vulnerability does

01Description

The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

Key dates

02Disclosure timeline

December 19, 2022 CVE published
April 14, 2025 Record updated