CVE-2023-33318: WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File Upload
Published Dec 20, 2023
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40.
Affected Software
1 affected component
WooCommerce Automatewoo Wordpress<=4.9.40
Remediation
Information
Update to 4.9.50 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33318?
The severity of CVE-2023-33318 is rated as high due to the unrestricted file upload vulnerability.
2
How do I fix CVE-2023-33318?
To fix CVE-2023-33318, update WooCommerce AutomateWoo to version 4.9.41 or later.
3
Which versions of WooCommerce AutomateWoo are affected by CVE-2023-33318?
CVE-2023-33318 affects WooCommerce AutomateWoo versions up to and including 4.9.40.
4
What are the risks associated with CVE-2023-33318?
The risks include potential remote code execution and unauthorized access to sensitive files.
5
Is there a workaround for CVE-2023-33318 if I cannot update?
As a temporary workaround for CVE-2023-33318, disable file upload functionalities in AutomateWoo until an update can be applied.