Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability has been identified in the Holest Engineering Spreadsheet Price Changer plugin for WooCommerce and WP E-commerce – Light, affecting versions through 2.4.37. This vulnerability allows unauthorized users to traverse directories and access restricted files on the server.
Impact
Exploitation of this vulnerability could lead to arbitrary file download, allowing attackers to download any file from the affected website, including sensitive files such as login credentials or backup files.
Remediation
Users are advised to update to a version of the Holest Engineering Spreadsheet Price Changer plugin for WooCommerce and WP E-commerce – Light that is later than 2.4.37. For those using WordPress, Patchstack offers a virtual patch that can be applied immediately.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
