WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload
CVE-2024-22152
8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 January 2024
What is CVE-2024-22152?
A vulnerability exists in WebToffee's Product Import Export for WooCommerce that allows the unrestricted upload of files with dangerous types. This risk can potentially allow malicious actors to upload executable files, posing a significant threat to the security of the WordPress environment. Affected versions include those prior to 2.3.7, highlighting the need for users to check and update their installations to safeguard against potential exploits.
Affected Version(s)
Product Import Export for WooCommerce <= 2.3.7