Arbitrary File Inclusion Vulnerability in WPC Smart Messages for WooCommerce
CVE-2024-10436
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 29 October 2024
What is CVE-2024-10436?
The WPC Smart Messages for WooCommerce plugin experiences a Local File Inclusion vulnerability in all versions up to and including 4.2.1. This issue arises through the get_condition_value function, allowing authenticated attackers with Subscriber-level access or greater to include and execute arbitrary files on the server. This exploit can facilitate the execution of any PHP code within those files, enabling attackers to bypass access controls, access sensitive information, or execute undesirable commands, particularly when handling file uploads deemed 'safe' like images.
Affected Version(s)
WPC Smart Messages for WooCommerce * <= 4.2.1