Product Input Fields for WooCommerce <= 2.0.1 - Unauthenticated Arbitrary File Upload
critical
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing file type validation based on file content, allowing any file type to be stored in the uploads directory without restriction. This makes it possible for un...
- CVSS:
- 9.8
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Aug 7, 2026
CVE-2026-19089 on NVD →
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.12.2
unknown
[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to uploa...
- Affected:
- up to 1.12.2
- Fixed in:
- 1.12.2
- Disclosed:
- Mar 8, 2025
CVE-2024-13359 on NVD →
Product Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File Upload
high
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to upload arb...
- CVSS:
- 8.1
- Affected:
- up to 1.12.0
- Fixed in:
- 1.12.1
- Disclosed:
- Mar 7, 2025
CVE-2024-13359 on NVD →
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 2.0
unknown
[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access a...
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Nov 26, 2024
CVE-2024-10857 on NVD →
Product Input Fields for WooCommerce <= 1.9 - Authenticated (Contributor+) Arbitrary File Read
medium
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and ab...
- CVSS:
- 6.5
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Nov 25, 2024
CVE-2024-10857 on NVD →
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.8.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Apr 15, 2024
CVE-2024-31431 on NVD →
Product Input Fields for WooCommerce <= 1.7.0 - Cross-Site Request Forgery to Notice Dismissal
medium
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation on the dismiss_notice() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 1.7.0
- Fixed in:
- 1.8.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31431 on NVD →
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7
unknown
[en] The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Jun 7, 2023
CVE-2020-36696 on NVD →
Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization
high
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.
- CVSS:
- 7.5
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 3, 2020
CVE-2020-36696 on NVD →
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7
unknown
Unauthenticated Arbitrary File Download vulnerability discovered by NinTechNet in WordPress Product Input Fields for WooCommerce plugin (versions <= 1.2.6).
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 3, 2020
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7
unknown
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 3, 2020
Product Input Fields for WooCommerce [product-input-fields-for-woocommerce] < 1.2.7
unknown
The lack of authorisation checks in the handle_downloads() function, hooked to admin_init() could allow unauthenticated users to download arbitrary files from the blog using a path traversal payload.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database