CVE Database /
CVE-2022-3762
CVE · Medium
CVE-2022-3762 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3762
|
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
6.5
|
< 5.6.5
|
5.6.5 |
2022-10-27 |
—
|
CVE-2022-3762
A vulnerability exists in the Booster for WooCommerce plugin for WordPress, allowing authenticated users with elevated permissions to download arbitrary files from the affected server. This is due to inadequate validation and sanitization of user-submitted data, specifically a parameter related to file names. As a result, attackers can exploit this weakness to obtain sensitive files from the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings