CVE-2024-13622
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 18, 2025
Updated: Feb 21, 2025
CWE ID 200
Summary
CVE-2024-13622: The File Uploads Addon for WooCommerce, a popular plugin for WordPress, has been identified as having a Sensitive Information Exposure vulnerability. This issue, present in all versions up to 1.7.1, allows unauthenticated attackers to access sensitive data stored in the /wp-content/uploads directory. The directory may contain confidential file attachments uploaded by customers, putting websites using this plugin at risk of data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share