CVE-2024-30231: WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability
Published Mar 26, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.
Affected Software
3 affected components
WebToffee Product Import Export For Woocommerce Wordpress<=2.4.1
WebToffee Product Import Export for WooCommerce<=2.4.1
WordPress Product Import Export for WooCommerce<=2.4.1
Remediation
Information
Update to 2.4.2 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30231?
CVE-2024-30231 is categorized as a critical vulnerability due to its potential for arbitrary file uploads.
2
How do I fix CVE-2024-30231?
To fix CVE-2024-30231, update the WebToffee Product Import Export for WooCommerce plugin to version 2.4.2 or later.
3
What versions of the product are affected by CVE-2024-30231?
CVE-2024-30231 affects WebToffee Product Import Export for WooCommerce versions from n/a up to 2.4.1.
4
What type of vulnerability is CVE-2024-30231?
CVE-2024-30231 is an Unrestricted Upload of File with Dangerous Type vulnerability.
5
Which product does CVE-2024-30231 pertain to?
CVE-2024-30231 pertains to the WebToffee Product Import Export for WooCommerce plugin.