First published: Mon May 06 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sendinblue | >n/a<=4.0.17 | |
WordPress Brevo for WooCommerce | <=4.0.17 |
Update to 4.0.18 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32807 is classified as a high severity vulnerability due to its potential for path traversal attacks.
To fix CVE-2024-32807, update the Brevo Sendinblue for WooCommerce plugin to version 4.0.18 or later.
A path traversal vulnerability, like CVE-2024-32807, allows an attacker to access files and directories that are outside the intended directory.
CVE-2024-32807 affects Brevo Sendinblue for WooCommerce versions from n/a through 4.0.17.
Yes, CVE-2024-32807 can affect WordPress sites using the Brevo for WooCommerce plugin up to version 4.0.17.