S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-33901 Scanner

CVE-2022-33901 scanner - Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-33901
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MultiSafepay plugin for WooCommerce (WordPress plugin)by MultiSafepay
<= 4.13.1
Updated Aug 22, 2026View on NVD →
Detail

The MultiSafepay plugin for WooCommerce plugin is a popular platform designed to provide secure payment options for businesses operating on WordPress. It is widely used by online retailers to facilitate fast and seamless transactions, ensuring a smooth shopping experience for customers all over the world. The plugin enables online merchants to accept various payment methods, including credit cards, iDEAL, PayPal, and many others. All transactions are processed through a secure payment gateway, providing the necessary data encryption and fraud prevention measures to safeguard against online threats. 

However, recently, a critical vulnerability has been detected in the MultiSafepay plugin for WooCommerce plugin, compromising the security of digital assets through the exploitation of an unauthenticated arbitrary file read vulnerability, tracked under CVE-2022-33901. This vulnerability allows an attacker to manipulate the plugin's files and directories without authorization, leading to data theft, system crashes, and other potential cyber threats. 

When exploited, this vulnerability can lead to severe consequences, including unauthorized access to confidential customer information, data breaches, and financial losses. Hackers can potentially gain complete access to sensitive customer data stored on the website's database, enabling them to exploit this information for their malicious ends. Additionally, the attacker can inject malicious code into the website, leading to the site's complete shutdown and loss of revenue. 

In conclusion, the MultiSafepay plugin for WooCommerce plugin is an essential tool for businesses operating on WordPress, providing a secure payment gateway to facilitate fast and seamless transactions. However, the recently detected CVE-2022-33901 vulnerability requires immediate action to prevent potential harm. By adhering to basic security precautions and using professional security tools like s4e.io, website owners can ensure their digital assets remain protected against cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, MultiSafepay plugin for WooCommerce users can take the following basic precautions:

  • Update the plugin to the latest version as soon as possible.
  • Ensure the website is protected by a firewall to prevent unauthorized access to sensitive files and directories.
  • Deploy an intrusion detection system (IDS) to monitor suspicious behavior and detect violations.
  • Perform regular security audits of the website to identify any potential security risks.
  • Train employees to recognize and respond to malicious behavior on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-33901 scanner - Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin for WordPress S4E