CVE-2022-44634 Details
Description
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
A directory traversal vulnerability allowing authenticated administrators to read arbitrary files has been identified in the S2W – Import Shopify to WooCommerce plugin, versions through 1.1.12, on WordPress. This vulnerability could be exploited to access files outside of the intended directory, potentially leading to the discovery of sensitive information or other files that could be used to compromise the site.
Users of the S2W – Import Shopify to WooCommerce plugin should update to version 1.1.13 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| villatheme s2w - import shopify to woocommerce | <= 1.1.12 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 22, 2022 | Initial Analysis | [email protected] |