CVE-2024-6500: InPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and Delete
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parserequest' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL). This makes it possible for unauthenticated attackers to read and delete arbitrary files on Windows servers. On Linux servers, only files within the WordPress install will be deleted, but all files can be read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6500?
CVE-2024-6500 has been assessed as a high severity vulnerability due to its potential for unauthorized data access and deletion.
How do I fix CVE-2024-6500?
To fix CVE-2024-6500, update the InPost for WooCommerce plugin to version 1.4.1 or later, and the InPost PL plugin to version 1.4.5 or later.
What are the affected versions of CVE-2024-6500?
CVE-2024-6500 affects InPost for WooCommerce versions up to and including 1.4.0 and InPost PL versions up to and including 1.4.4.
What is the nature of vulnerability CVE-2024-6500?
CVE-2024-6500 is a vulnerability that allows unauthorized access and deletion of data due to a missing capability check in the 'parse_request' function.
Who is affected by CVE-2024-6500?
Anyone using the InPost for WooCommerce plugin versions up to 1.4.0 or the InPost PL plugin versions up to 1.4.4 is affected by CVE-2024-6500.