Local File Inclusion Vulnerability in Woocommerce Blocks - Woolook Plugin by WordPress
CVE-2024-8393
6.6MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2025
What is CVE-2024-8393?
The Woocommerce Blocks - Woolook plugin for WordPress is susceptible to a Local File Inclusion vulnerability. This issue affects all versions up to and including 1.7.0, where insufficient validation of the 'tab' parameter can be exploited by authenticated attackers with Administrator-level access or higher. This allows the inclusion and execution of arbitrary files on the server. Attackers can leverage this vulnerability to execute PHP code from uploaded files, bypass access controls, or extract sensitive information. Additionally, techniques such as Cross-Site Request Forgery (CSRF) can be used to facilitate the exploitation of this vulnerability.
Affected Version(s)
Woocommerce Blocks – Woolook * <= 1.7.0