CVE-2024-13355

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 434

Summary

CVE-2024-13355 is a vulnerability affecting the WooCommerce: OrderConvo plugin for WordPress. The issue lies in the insufficient file type validation in the upload_file() function, which allows authenticated attackers with Subscriber-level access and above to upload files. This vulnerability poses a significant risk, as attackers can potentially execute remote code or inject Cross-Site Scripting (XSS) code on the affected site. Versions up to 13.2 of the plugin are impacted by this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share