Local File Inclusion Vulnerability in Woocommerce Blocks - Woolook Plugin by WordPress
CVE-2024-8393

6.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2025

What is CVE-2024-8393?

The Woocommerce Blocks - Woolook plugin for WordPress is susceptible to a Local File Inclusion vulnerability. This issue affects all versions up to and including 1.7.0, where insufficient validation of the 'tab' parameter can be exploited by authenticated attackers with Administrator-level access or higher. This allows the inclusion and execution of arbitrary files on the server. Attackers can leverage this vulnerability to execute PHP code from uploaded files, bypass access controls, or extract sensitive information. Additionally, techniques such as Cross-Site Request Forgery (CSRF) can be used to facilitate the exploitation of this vulnerability.

Affected Version(s)

Woocommerce Blocks – Woolook * <= 1.7.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

paulmockford
.
CVE-2024-8393 : Local File Inclusion Vulnerability in Woocommerce Blocks - Woolook Plugin by WordPress