Vulnerability Description
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Woocommerce | Woocommerce | < 3.4.6 |
Related Weaknesses (CWE)
References
- https://blog.ripstech.com/2018/wordpress-design-flaw-leads-to-woocommerce-rce/Third Party Advisory
- https://blog.ripstech.com/2018/wordpress-design-flaw-leads-to-woocommerce-rce/Third Party Advisory
FAQ
What is CVE-2018-20714?
CVE-2018-20714 is a vulnerability with a CVSS score of 8.1 (HIGH). The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privi...
How severe is CVE-2018-20714?
CVE-2018-20714 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20714?
Check the references section above for vendor advisories and patch information. Affected products include: Woocommerce Woocommerce.