The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-27T08:58:44

Updated: 2024-08-03T00:24:42.631Z

Reserved: 2022-05-31T00:00:00

Link: CVE-2022-1953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-27T09:15:10.333

Modified: 2022-07-06T17:16:18.023

Link: CVE-2022-1953

cve-icon Redhat

No data.