CVE-2022-45377: WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45377?
CVE-2022-45377 is classified as a high severity vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2022-45377?
To fix CVE-2022-45377, update the Drag and Drop Multiple File Upload for WooCommerce plugin to version 1.0.9 or later.
What software is affected by CVE-2022-45377?
CVE-2022-45377 affects the Drag and Drop Multiple File Upload for WooCommerce plugin versions prior to 1.0.9.
What type of attack does CVE-2022-45377 enable?
CVE-2022-45377 enables attackers to upload files of dangerous types, which can lead to arbitrary code execution.
Is CVE-2022-45377 specific to certain WordPress versions?
CVE-2022-45377 specifically affects the Drag and Drop Multiple File Upload for WooCommerce plugin on WordPress, irrespective of the WordPress version used.