Sanitize $handle in the admin log page to prevent XSS, and a check if the log file which is about to be deleted also really exists in the log directory.

This vulnerability affects the following application versions:

  • WooCommerce 3.4.4
  • WooCommerce 3.4.5
  • WooCommerce 3.5.0-beta.1
  • WooCommerce 3.5.0-rc.1

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *