CVE-2024-13922

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Mar 26, 2025
CWE ID 73

Summary

CVE-2024-13922 is a vulnerability affecting the Order Export & Order Import plugin for WooCommerce on WordPress. This issue arises due to insufficient file path validation within the admin_log_page() function, allowing authenticated attackers with Administrator-level access to delete arbitrary log files on the server. This presents a significant risk, as crucial system files may be inadvertently erased, potentially leading to significant data loss or system compromise. All versions up to and including 2.6.0 are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share