CVE-2024-9756
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.
- Affected products
- Order Attachments For Woocommerce
- Directsoftware Order Attachments For Woocommerce
- < 2.5.0
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-862
- NVD status
- Analyzed
- Published
- 2024-10-12
CVE-2024-9756 at NVD
2 known exploits for CVE-2024-9756
Proof-of-concept code and exploit modules indexed by Sploitus