CVE-2024-27971: WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27971?
CVE-2024-27971 is classified as a high severity vulnerability due to its potential for local file inclusion.
How do I fix CVE-2024-27971?
To fix CVE-2024-27971, update the Premmerce Permalink Manager for WooCommerce plugin to version 2.3.11 or later.
What software is affected by CVE-2024-27971?
CVE-2024-27971 affects versions of the Premmerce Permalink Manager for WooCommerce plugin up to and including 2.3.10.
What type of vulnerability is CVE-2024-27971?
CVE-2024-27971 is a Path Traversal vulnerability, allowing improper limitation of a pathname to a restricted directory.
Can CVE-2024-27971 lead to remote exploits?
Yes, CVE-2024-27971 can potentially allow attackers to execute local files, leading to further compromises of the system.