Sploitus

CVE-2022-4298

1 known exploit for CVE-2022-4298

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

Affected products
Wholesale Market
Cedcommerce Wholesale Market
< 2.2.1
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
1.8% (77th percentile)
NVD status
Modified
Published
2023-01-02
CVE-2022-4298 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-4298

Proof-of-concept code and exploit modules indexed by Sploitus