CVE-2024-13622

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 21, 2025
CWE ID 200

Summary

CVE-2024-13622: The File Uploads Addon for WooCommerce, a popular plugin for WordPress, has been identified as having a Sensitive Information Exposure vulnerability. This issue, present in all versions up to 1.7.1, allows unauthenticated attackers to access sensitive data stored in the /wp-content/uploads directory. The directory may contain confidential file attachments uploaded by customers, putting websites using this plugin at risk of data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share