vendor:
WordPress
by:
fu2x2000
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: WordPress
Affected Version From: WordPress 4.8.3
Affected Version To: woocommerce 2.0/3.0
Patch Exists: YES
Related CWE: 2017-17058
CPE: a:wordpress:wordpress
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Webapps
2017
WordPress woocommerce directory traversal
Identifying woo commerce theme pluging properly sanitized against Directory Traversal,even the latest version of WordPress with woocommerce can be vulnerable.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in a filesystem operation.