CVE-2024-13744

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 9, 2025
CWE ID 434

Summary

CVE-2024-13744 is a vulnerability affecting the Booster for WooCommerce plugin used in WordPress sites. The issue lies in the validate_product_input_fields_on_add_to_cart function, where file type validation is missing in versions 4.0.1 to 7.2.4. This oversight enables unauthenticated attackers to upload arbitrary files on the server, posing a potential risk for remote code execution. The vulnerability could lead to serious consequences, including site takeover and data breaches. It is recommended that users update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share