WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File Upload
CVE-2023-33318

9.9CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 December 2023

Summary

The vulnerability in WooCommerce AutomateWoo allows an unrestricted upload of files with potentially dangerous types. This issue affects all versions up to 4.9.40, posing a security risk that could lead to unauthorized access or execution of malicious programs on the server.

Affected Version(s)

AutomateWoo <= 4.9.40

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.