PT-2025-2130 · WordPress · Admin/Customer Messages After Order For Woocommerce: Orderconvo
1337_Wannabe
+1
·
Published
2025-01-16
·
Updated
2025-01-16
·
CVE-2024-13355
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress versions up to, and including, 13.2
Description
The issue is related to insufficient file type validation in the
upload file() function, which allows authenticated attackers with Subscriber-level access and above to upload files on the affected site's server. This may make remote code execution possible and is confirmed to make Cross-Site Scripting possible.Recommendations
For versions up to, and including, 13.2, update to a version that includes a fix for the insufficient file type validation in the
upload file() function.
As a temporary workaround, consider disabling the upload file() function until a patch is available.
Restrict access to the file upload feature to minimize the risk of exploitation.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin/Customer Messages After Order For Woocommerce: Orderconvo