PT-2024-36766 · Woocommerce · Dynamic Product Category Grid

João Pedro S Alcântara

·

Published

2024-12-31

·

Updated

2025-01-05

·

CVE-2024-56230

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dynamic Product Category Grid, Slider for WooCommerce versions 1.1.3 and earlier
Description The issue is related to improper control of filename for Include/Require Statement in PHP Program, allowing PHP Local File Inclusion. This problem can be exploited through the Inclusión de archivo remoto PHP or 'PHP Remote File Inclusion' vulnerability.
Recommendations For versions 1.1.3 and earlier, update to a version later than 1.1.3 to resolve the issue. As a temporary workaround, consider restricting access to vulnerable PHP files until a patch is available. Avoid using the vulnerable Include/Require statement in the affected PHP program until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-56230

Affected Products

Dynamic Product Category Grid