CVE-2024-10627: WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxmanagefilechunkupload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10627?
CVE-2024-10627 is classified as a high severity vulnerability due to its potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2024-10627?
To fix CVE-2024-10627, update the WooCommerce Support Ticket System plugin to the latest version beyond 17.7 that includes the necessary file type validation.
Which versions are affected by CVE-2024-10627?
All versions of the WooCommerce Support Ticket System plugin up to and including 17.7 are affected by CVE-2024-10627.
What can attackers do with CVE-2024-10627?
Attackers can exploit CVE-2024-10627 to upload malicious files to the server, potentially compromising the website.
Is authentication required to exploit CVE-2024-10627?
No, CVE-2024-10627 can be exploited by unauthenticated attackers, making it particularly dangerous.