CVE-2024-10626

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 22

Summary

CVE-2024-10626 is a vulnerability affecting the WooCommerce Support Ticket System plugin for WordPress. The issue lies in the insufficient file path validation in the delete_uploaded_file() function, present in all versions up to 17.7. This oversight enables authenticated attackers, even those with low-level Subscriber access, to delete arbitrary files on the server. Deleting a critical file, such as wp-config.php, can result in remote code execution, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share