CVE-2024-10626
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 22
Summary
CVE-2024-10626 is a vulnerability affecting the WooCommerce Support Ticket System plugin for WordPress. The issue lies in the insufficient file path validation in the delete_uploaded_file() function, present in all versions up to 17.7. This oversight enables authenticated attackers, even those with low-level Subscriber access, to delete arbitrary files on the server. Deleting a critical file, such as wp-config.php, can result in remote code execution, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.