Lucene search

K
wpvulndbWpvulndbWPVDB-ID:48A6071B-86B0-41C8-A67E-877DECE29A0D
HistoryJan 12, 2024 - 12:00 a.m.

Customer Reviews for WooCommerce < 5.38.10 - Author+ Arbitrary File Upload

2024-01-1200:00:00
wpscan.com
6
customer reviews
woocommerce
arbitrary file upload
missing validation
ajax action
authenticated attackers
remote code execution

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

59.8%

Description The plugin is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site’s server which may make remote code execution possible.

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

59.8%

Related for WPVDB-ID:48A6071B-86B0-41C8-A67E-877DECE29A0D