Local File Inclusion Vulnerability in Woocommerce Blocks - Woolook Plugin by WordPress
CVE-2024-8393
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2025
What is CVE-2024-8393?
The Woocommerce Blocks - Woolook plugin for WordPress is susceptible to a Local File Inclusion vulnerability. This issue affects all versions up to and including 1.7.0, where insufficient validation of the 'tab' parameter can be exploited by authenticated attackers with Administrator-level access or higher. This allows the inclusion and execution of arbitrary files on the server. Attackers can leverage this vulnerability to execute PHP code from uploaded files, bypass access controls, or extract sensitive information. Additionally, techniques such as Cross-Site Request Forgery (CSRF) can be used to facilitate the exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Woocommerce Blocks β Woolook * <= 1.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved