CVE-2024-35634: Woocommerce – Recent Purchases plugin <= 1.0.1 - File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35634?
CVE-2024-35634 is classified as a medium-severity vulnerability due to its potential for local file inclusion.
How do I fix CVE-2024-35634?
To remediate CVE-2024-35634, update the Woocommerce – Recent Purchases plugin to version 1.0.2 or later.
What type of vulnerability is CVE-2024-35634?
CVE-2024-35634 is a Path Traversal vulnerability that allows for improper limitation of a pathname.
Which versions of Woocommerce – Recent Purchases are affected by CVE-2024-35634?
CVE-2024-35634 affects Woocommerce – Recent Purchases versions up to and including 1.0.1.
Does CVE-2024-35634 affect other plugins besides Woocommerce – Recent Purchases?
CVE-2024-35634 is specific to the Woocommerce – Recent Purchases plugin and does not affect other plugins.