PT-2023-28284 · WordPress · Orders Tracking For Woocommerce

Utkarsh Agrawal

·

Published

2023-09-04

·

Updated

2023-09-08

·

CVE-2023-4216

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Orders Tracking for WooCommerce WordPress plugin version 1.2.5 and earlier
Description The issue allows high privilege users with the manage woocommerce capability to access any file on the web server via a Traversal attack when importing a CSV file, due to the lack of validation of the file url parameter. The content retrieved is limited to the first line of the file.
Recommendations For versions prior to 1.2.6, update to version 1.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the CSV import feature to minimize the risk of exploitation. Avoid using the file url parameter in the affected import functionality until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2023-4216

Affected Products

Orders Tracking For Woocommerce