Arbitrary File Upload Vulnerability in Product Input Fields for WooCommerce by WordPress
CVE-2024-13359
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-13359?
The Product Input Fields for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to inadequate validation of file types in the add_product_input_fields_to_order_item_meta() function. This vulnerability exists in all versions up to and including 1.12.1. An unauthenticated attacker could exploit this flaw to upload unauthorized files to the server. By default, this vulnerability is primarily associated with double extension file upload attacks. However, if the field that restricts accepted file extensions is left empty by an administrator, it may allow .php files to be uploaded, enabling potential remote code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Product Input Fields for WooCommerce * <= 1.12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved