Vulnerability Details CVE-2022-4298
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.12
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-4298
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.0
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.1
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.10
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.11
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.2
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.3
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.4
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.5
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.6
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.7
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.8
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.9
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.0
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.1
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.10
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.11
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.12
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.2
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.3
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.4
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.5
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.6
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.7
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.8
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.9
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.1
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.2
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.3
-
cpe:2.3:a:cedcommerce:wholesale_market:2.2.0