PT-2021-3982 · WordPress · Woocommerce Stock Manager

Chloe Chamberland

·

Published

2021-03-19

·

Updated

2023-07-18

·

CVE-2021-34619

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Stock Manager versions up to, and including, 2.5.7
Description The issue is related to the implementation of the import/export functionality in the WooCommerce Stock Manager plugin for WordPress, specifically in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file. It allows for unlimited upload of dangerous file types. This can be exploited by a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially leading to arbitrary file upload due to missing nonce and file validation.
Recommendations For versions up to, and including, 2.5.7, update to a version that includes the necessary nonce and file validation to prevent CSRF attacks and arbitrary file uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

CSRF

Weakness Enumeration

Related Identifiers

BDU:2021-04503
CVE-2021-34619

Affected Products

Woocommerce Stock Manager