CVE-2024-1205
CVE-2024-1205 allows arbitrary file uploads in the Management App for WooCommerce WordPress plugin. This vulnerability affects versions up to 1.2.0, enabling authenticated attackers with subscriber access to upload malicious files. Although the CVSS score is 8.8 indicating high severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30. While not critical based on the SVRS, the potential for remote code execution makes this a serious issue. The missing file type validation in the nouvello_upload_csv_file function is the root cause. Successful exploitation could lead to complete system compromise. Users should update to a patched version of the plugin immediately to mitigate the risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.