PT-2024-16420 · WordPress · Woocommerce Support Ticket System

Tonn

·

Published

2024-11-08

·

Updated

2024-11-14

·

CVE-2024-10626

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Support Ticket System plugin for WordPress versions up to, and including, 17.7
Description The issue is related to arbitrary file deletion due to insufficient file path validation in the delete uploaded file() function. This allows authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server, potentially leading to remote code execution if critical files like wp-config.php are deleted.
Recommendations For versions up to, and including, 17.7, update to a version that fixes the delete uploaded file() function issue to prevent arbitrary file deletion. As a temporary workaround, consider disabling the delete uploaded file() function until a patch is available to minimize the risk of exploitation.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10626

Affected Products

Woocommerce Support Ticket System