WordPress Plugin Vulnerabilities

Woocommerce Stock Manager < 2.6.0 - CSRF to Arbitrary File Upload

Description

The plugin is vulnerable to CSRF leading to Arbitrary File Upload due to missing nonce and file validation in the /admin/views/import-export.php file.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-06-14 (about 4 years ago)
Added
2021-06-14 (about 4 years ago)
Last Updated
2021-06-25 (about 4 years ago)

Other