CVE-2024-22152: WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.3.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WebToffee Product Import Export for WooCommerce (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.3.8
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22152?
CVE-2024-22152 is classified as a high severity vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2024-22152?
To mitigate CVE-2024-22152, upgrade the WebToffee Product Import Export for WooCommerce plugin to version 2.3.8 or later.
What software is affected by CVE-2024-22152?
CVE-2024-22152 affects the WebToffee Product Import Export for WooCommerce plugin versions prior to 2.3.8.
What type of attack is possible with CVE-2024-22152?
CVE-2024-22152 allows attackers to upload files with dangerous types, which can lead to potential exploitation of the server.
Is CVE-2024-22152 a remote or local vulnerability?
CVE-2024-22152 is classified as a remote vulnerability, allowing an attacker to exploit it from outside the affected system.