CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vanquish 1Woocommerce Upload Files Nov 19, 2024 Nov 13, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possi...Show more |
1Vanquish 1Woocommerce Upload Files Nov 25, 2024 Apr 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "bl...Show more |