WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File Upload
critical
The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may...
- CVSS:
- 9.8
- Affected:
- up to 84.3
- Fixed in:
- 84.4
- Disclosed:
- Nov 12, 2024
CVE-2024-10820 on NVD →
WooCommerce Upload Files <= 59.3 - Arbitrary File Upload
critical
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also p...
- CVSS:
- 9.8
- Affected:
- up to 59.4
- Fixed in:
- 59.4
- Disclosed:
- Mar 4, 2021
CVE-2021-24171 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database