PT-2024-21218 · WordPress · Woocommerce Checkout Field Editor

Dave Jong

·

Published

2024-02-26

·

Updated

2024-02-26

·

CVE-2024-25925

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Easy Checkout Field Editor, Fees & Discounts versions n/a through 3.5.12
Description The issue is related to an Unrestricted Upload of File with Dangerous Type, which affects the specified versions of WooCommerce Easy Checkout Field Editor, Fees & Discounts. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions n/a through 3.5.12, update to a version later than 3.5.12 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-25925

Affected Products

Woocommerce Checkout Field Editor