PT-2026-81963 · WordPress · Order Tip For Woocommerce
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Order Tip for WooCommerce versions prior to 1.6.0
Description
Insufficient capability checks and a lack of path restriction in the
delete exported csv file ajax function allow users with the Shop Manager role or higher to delete arbitrary files on the server. This flaw could potentially lead to a complete site takeover.Recommendations
Update Order Tip for WooCommerce to version 1.6.0 or later.
As a temporary mitigation, restrict access to the
delete exported csv file ajax function for users with the Shop Manager role.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Order Tip For Woocommerce