WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload
CVE-2024-22152

8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 January 2024

What is CVE-2024-22152?

A vulnerability exists in WebToffee's Product Import Export for WooCommerce that allows the unrestricted upload of files with dangerous types. This risk can potentially allow malicious actors to upload executable files, posing a significant threat to the security of the WordPress environment. Affected versions include those prior to 2.3.7, highlighting the need for users to check and update their installations to safeguard against potential exploits.

Affected Version(s)

Product Import Export for WooCommerce <= 2.3.7

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dateoljo of BoB 12th (Patchstack Alliance)
.