CVE · High

CVE-2018-20714 — WooCommerce [woocommerce] < 3.4.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-20714 WooCommerce [woocommerce] < 3.4.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.1 < 3.4.6 3.4.6 2018-11-06

CVE-2018-20714

WooCommerce versions prior to 3.4.6 contain a file deletion flaw in the logging mechanism that permits attackers to remove the woocommerce.php file. This removal bypasses critical privilege validation routines, enabling users with shop manager permissions to gain administrative access to the WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.