CVE-2024-13744: Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validateproductinputfieldsonaddtocart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13744?
CVE-2024-13744 is considered a high severity vulnerability due to the potential for unauthenticated file uploads.
How do I fix CVE-2024-13744?
To fix CVE-2024-13744, update the Booster for WooCommerce plugin to a version above 7.2.4.
What versions of Booster for WooCommerce are affected by CVE-2024-13744?
CVE-2024-13744 affects versions of Booster for WooCommerce from 4.0.1 to 7.2.4.
Who can exploit CVE-2024-13744?
CVE-2024-13744 can be exploited by unauthenticated attackers to upload arbitrary files.
What kind of attack does CVE-2024-13744 enable?
CVE-2024-13744 enables attacks involving arbitrary file uploads, which can compromise the WordPress site.