PT-2025-35202 · Unknown +1 · Woocommerce +1

Lucky_Buddy

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2024-13342

CVSS v3.1
8.1
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Booster for WooCommerce versions up to and including 7.2.4

Description:

The Booster for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to the absence of file type validation within the `add files to order` function. This allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the affected server, contingent upon specific configuration settings that execute the first file extension present.

Recommendations:

Update Booster for WooCommerce to a version later than 7.2.4.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-13342

Affected Products

Booster For Woocommerce
Woocommerce