CVE-2024-1986
CVE-2024-1986 affects the Booster Elite for WooCommerce plugin for WordPress, allowing arbitrary file uploads. This vulnerability stems from missing file type validation in the wc_add_new_product() function, impacting versions up to 7.1.7. While the CVSS score is 8.8, SOCRadar's Vulnerability Risk Score (SVRS) is 30, indicating lower immediate risk than other critical vulnerabilities with higher SVRS scores. Customer-level attackers can upload arbitrary files, potentially leading to remote code execution, but only if user product uploads are enabled. The flaw, categorized under CWE-434, highlights risks associated with unrestricted file uploads. Despite a lower SVRS, vigilance is recommended to prevent exploitation. This is significant because successful exploitation allows attackers to run malicious code on the server, compromising the entire website.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.