First published: Tue Jun 04 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Woocommerce - Recent Purchases Wordpress | <=1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35634 is classified as a medium-severity vulnerability due to its potential for local file inclusion.
To remediate CVE-2024-35634, update the Woocommerce – Recent Purchases plugin to version 1.0.2 or later.
CVE-2024-35634 is a Path Traversal vulnerability that allows for improper limitation of a pathname.
CVE-2024-35634 affects Woocommerce – Recent Purchases versions up to and including 1.0.1.
CVE-2024-35634 is specific to the Woocommerce – Recent Purchases plugin and does not affect other plugins.