CVE Database /
CVE-2018-20714
CVE · High
CVE-2018-20714 — WooCommerce [woocommerce] < 3.4.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-20714
|
WooCommerce [woocommerce] < 3.4.6 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
8.1
|
< 3.4.6
|
3.4.6 |
2018-11-06 |
—
|
CVE-2018-20714
WooCommerce versions prior to 3.4.6 contain a file deletion flaw in the logging mechanism that permits attackers to remove the woocommerce.php file. This removal bypasses critical privilege validation routines, enabling users with shop manager permissions to gain administrative access to the WordPress site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings