Vulnerability Details CVE-2022-4298
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.218
EPSS Ranking 95.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-4298
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.0
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.1
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.10
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.11
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.2
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.3
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.4
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.5
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.6
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.7
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.8
-
cpe:2.3:a:cedcommerce:wholesale_market:1.0.9
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.0
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.1
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.10
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.11
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.12
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.2
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.3
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.4
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.5
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.6
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.7
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.8
-
cpe:2.3:a:cedcommerce:wholesale_market:2.0.9
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.1
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.2
-
cpe:2.3:a:cedcommerce:wholesale_market:2.1.3
-
cpe:2.3:a:cedcommerce:wholesale_market:2.2.0