PT-2024-38215 · WordPress · Woocommerce Google Feed Manager

Lucio Sá

·

Published

2024-08-22

·

Updated

2024-09-27

·

CVE-2024-7258

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Google Feed Manager plugin for WordPress versions 1.0 through 2.8.0
Description The issue is due to a missing capability check on the wppfm removeFeedFile function, allowing authenticated attackers with Contributor-level access and above to delete arbitrary files on the server. This can lead to remote code execution when the right file is deleted, such as wp-config.php.
Recommendations For versions 1.0 through 2.8.0, upgrade to version 2.8.1 to remediate the issue. As a temporary workaround, consider restricting access to the wppfm removeFeedFile function to prevent unauthorized file deletion.

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7258

Affected Products

Woocommerce Google Feed Manager