QID 731236

Date Published: 2024-03-11

QID 731236: WordPress Woocommerce-jetpack Arbitrary File Upload Vulnerability

Booster combines everything you need to fully customize your sites functionality into a single WooCommerce bundle with 110 features and counting. With zero coding needed and easy setup options Booster makes customization simple for everyone.

CVE-2024-1986 : The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product function in all versions up to and including 7.1.7. Affected Versions:
WordPress Woocommerce-jetpack before 7.1.8

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Woocommerce-jetpack Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability could allow an unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible..

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to install Woocommerce-jetpack 7.1.8 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731236

    Software Advisories
    Advisory ID Software Component Link
    woocommerce-jetpack URL Logo wordpress.org/plugins/woocommerce-jetpack/#developers