Description
WordPress Plugin Correos Woocommerce is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Correos Woocommerce version 1.3.0.0 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842)
MediaWiki Incorrect Authorization Vulnerability (CVE-2023-22945)
PHP NULL Pointer Dereference Vulnerability (CVE-2016-7130)
Django Improper Input Validation Vulnerability (CVE-2012-4520)
Data Tables Generator by Supsystic Multiple Vulnerabilities (1.9.91)