PT-2024-28534 · Woocommerce · Booster For Woocommerce
Matthew Rollings
+1
·
Published
2024-05-02
·
Updated
2025-02-03
·
CVE-2024-3957
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The Booster for WooCommerce plugin versions up to, and including, 7.1.8
Description
The issue allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability of this issue depend on what other plugins are installed and the shortcode functionality they provide.
Recommendations
For versions up to, and including, 7.1.8, update to a version later than 7.1.8 to resolve the issue. As a temporary workaround, consider restricting access to shortcode functionality to minimize the risk of exploitation.
Fix
Incorrect Authorization
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Booster For Woocommerce