Access violation vulnerability in W2S – Migrate WooCommerce to Shopify 1.2.1

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is at risk of being exploited through an Arbitrary File Read vulnerability. This vulnerability exists in all versions up to and including 1.2.1 and can be triggered by using the ‘viw2s_view_log’ AJAX action. It allows attackers who have been authenticated and have at least Subscriber-level access to read the contents of any file on the server. This could potentially expose sensitive information.

Detected in:

W2S – Migrate WooCommerce to Shopify fixed vulnerable versions: >= * <= 1.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.