CVE-2024-33566: WordPress OrderConvo plugin <= 12.4 - Unauthenticated API Access to Arbitrary File Upload vulnerability
Published Apr 29, 2024
·Updated
Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
Affected Software
1 affected component
N-Media OrderConvo<=12.4
Remediation
Information
Update to 12.5 or a higher version.
Event History
Apr 29, 2024
CVE Published
via MITRE·07:58 AM
Data Sourced
via MITRE·07:58 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33566?
CVE-2024-33566 has a severity rating that indicates a critical risk due to potential OS Command Injection.
2
How do I fix CVE-2024-33566?
To fix CVE-2024-33566, update N-Media OrderConvo to a version higher than 12.4.
3
What types of systems are affected by CVE-2024-33566?
CVE-2024-33566 affects N-Media OrderConvo and WordPress OrderConvo versions up to and including 12.4.
4
What is the impact of CVE-2024-33566?
The impact of CVE-2024-33566 includes unauthorized access that allows attackers to execute arbitrary commands on the server.
5
Is CVE-2024-33566 exploitable remotely?
Yes, CVE-2024-33566 can be exploited remotely without authentication.