CVE-2024-10625: WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deletetmpuploadedfile() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10625?
CVE-2024-10625 is considered a high-severity vulnerability due to its potential for arbitrary file deletion.
How do I fix CVE-2024-10625?
To fix CVE-2024-10625, upgrade the WooCommerce Support Ticket System plugin to version 17.8 or later.
Who is affected by CVE-2024-10625?
CVE-2024-10625 affects all versions of the WooCommerce Support Ticket System plugin up to and including version 17.7.
Can CVE-2024-10625 be exploited remotely?
Yes, CVE-2024-10625 can be exploited by unauthenticated attackers, allowing them to delete arbitrary files.
What is the impact of CVE-2024-10625?
The impact of CVE-2024-10625 may include data loss and potential system compromise through file deletion.