CVE-2024-13831
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-13638 is a vulnerability affecting the Order Attachments plugin for WooCommerce on WordPress. In versions up to 2.5.1, this issue exposes sensitive information due to insecure storage of data in the '/wp-content/uploads' directory. Unauthenticated attackers can exploit this vulnerability and gain access to file attachments added to orders, potentially exposing confidential information. By taking advantage of this Sensitive Information Exposure flaw, attackers can obtain valuable data, posing a significant risk to WordPress sites using the Order Attachments plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.