CVE-2024-13744
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-13744 is a vulnerability affecting the Booster for WooCommerce plugin used in WordPress sites. The issue lies in the validate_product_input_fields_on_add_to_cart function, where file type validation is missing in versions 4.0.1 to 7.2.4. This oversight enables unauthenticated attackers to upload arbitrary files on the server, posing a potential risk for remote code execution. The vulnerability could lead to serious consequences, including site takeover and data breaches. It is recommended that users update to the latest version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Booster