PT-2024-28589 · Woocommerce · Woocommerce Pdf Vouchers

Dave Jong

·

Published

2024-08-13

·

Updated

2026-01-28

·

CVE-2024-39651

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce PDF Vouchers versions prior to 4.9.5
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a 'Path Traversal' vulnerability, which allows File Manipulation. This vulnerability affects the WooCommerce PDF Vouchers plugin.
Recommendations Update to version 4.9.5 to secure against this threat. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-39651

Affected Products

Woocommerce Pdf Vouchers