PT-2022-14213 · WordPress · Staggs Product Configurator For Woocommerce

Cydave

·

Published

2022-06-27

·

Updated

2022-07-06

·

CVE-2022-1953

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Product Configurator for WooCommerce WordPress plugin versions prior to 1.2.32
Description The issue allows unauthenticated users to delete arbitrary files via an AJAX action. This is possible because the AJAX action accepts user input that is used in a path and passed to the unlink() function without validation.
Recommendations For versions prior to 1.2.32, update to version 1.2.32 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action until a patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1953

Affected Products

Staggs Product Configurator For Woocommerce