CVE-2024-32807: WordPress Brevo for WooCommerce plugin <= 4.0.17 - Arbitrary File Download and Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32807?
CVE-2024-32807 is classified as a high severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2024-32807?
To fix CVE-2024-32807, update the Brevo Sendinblue for WooCommerce plugin to version 4.0.18 or later.
What is a path traversal vulnerability in CVE-2024-32807?
A path traversal vulnerability, like CVE-2024-32807, allows an attacker to access files and directories that are outside the intended directory.
Which versions of Brevo Sendinblue for WooCommerce are affected by CVE-2024-32807?
CVE-2024-32807 affects Brevo Sendinblue for WooCommerce versions from n/a through 4.0.17.
Can CVE-2024-32807 affect my WordPress site?
Yes, CVE-2024-32807 can affect WordPress sites using the Brevo for WooCommerce plugin up to version 4.0.17.