CVE-2024-44048: WordPress Product Carousel Slider & Grid Ultimate for WooCommerce plugin <= 1.9.10 - Authenticated Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through <= 1.9.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44048?
CVE-2024-44048 has a severity rating that indicates a significant risk due to its ability to allow local file inclusion.
How do I fix CVE-2024-44048?
To fix CVE-2024-44048, update the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce to the latest version above 1.9.10.
What version of wpWax Product Carousel Slider & Grid Ultimate for WooCommerce is affected by CVE-2024-44048?
CVE-2024-44048 affects versions of wpWax Product Carousel Slider & Grid Ultimate for WooCommerce from n/a up to and including 1.9.10.
What type of vulnerability is CVE-2024-44048?
CVE-2024-44048 is classified as a 'Path Traversal' vulnerability allowing PHP local file inclusion.
Is there a workaround for CVE-2024-44048?
There are no known workarounds for CVE-2024-44048; updating to a patched version is necessary.