Path Traversal Vulnerability Affects Checkout Field Editor for WooCommerce (Pro)
CVE-2024-35658

8.6HIGH

What is CVE-2024-35658?

The vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) stems from improper limitations on pathnames, which can lead to a Path Traversal condition. This issue could allow unauthorized users to manipulate files, potentially causing functionality misuse. The affected versions range from any version leading up to 3.6.2.

Affected Version(s)

Checkout Field Editor for WooCommerce (Pro) <= 3.6.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.