CVE · Medium

CVE-2022-3762 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3762 Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 5.6.5 5.6.5 2022-10-27

CVE-2022-3762

A vulnerability exists in the Booster for WooCommerce plugin for WordPress, allowing authenticated users with elevated permissions to download arbitrary files from the affected server. This is due to inadequate validation and sanitization of user-submitted data, specifically a parameter related to file names. As a result, attackers can exploit this weakness to obtain sensitive files from the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.