The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/a0bc4b13-53fe-462d-8306-8915196d3a5a/ | third party advisory vdb entry exploit technical description |
https://jetpack.com/2021/07/22/severe-vulnerability-patched-in-woocommerce-currency-switcher/ | third party advisory exploit |