CVE-2024-39651: WordPress WooCommerce PDF Vouchers plugin < 4.9.5 - Unauthenticated Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39651?
The severity of CVE-2024-39651 is classified as high due to its potential to allow unauthorized file manipulation.
How do I fix CVE-2024-39651?
To fix CVE-2024-39651, update the WPWeb WooCommerce PDF Vouchers plugin to version 4.9.5 or later.
What is the impact of CVE-2024-39651 on affected systems?
CVE-2024-39651 allows attackers to exploit path traversal vulnerabilities leading to unauthorized file manipulation on affected systems.
What versions of WPWeb WooCommerce PDF Vouchers are affected by CVE-2024-39651?
CVE-2024-39651 affects all versions of WPWeb WooCommerce PDF Vouchers prior to version 4.9.5.
Is there any mitigation for CVE-2024-39651 before updating?
While the best course of action is to update, temporary mitigation includes restricting file permissions and monitoring file changes on affected systems.