CVE-2022-4109

CVE-2022-4109: Wholesale Market for WooCommerce < 2.0.0 - Admin+ Arbitrary Log Download

Vendor Unknown
Product Wholesale Market for WooCommerce
Published January 2, 2023
Last update April 10, 2025

CVSS base score

What the vulnerability does

01Description

The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

Key dates

02Disclosure timeline

January 2, 2023 CVE published
April 10, 2025 Record updated