What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.3.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.3.7.
Explanation of Vulnerability in Simple Terms
Product Import Export for WooCommerce versions up to 2.3.7 allow administrators to upload files without proper validation. An attacker with admin access can upload malicious files to compromise the site's integrity and confidentiality. The vulnerability affects file handling across the entire WordPress installation due to scope change.
What an attacker can do
Upload malicious files to the WordPress site and execute code or access sensitive data.
Potential impact on your site
A compromised admin account can upload files that execute code or expose sensitive information across your entire site.
Conditions required to exploit
Attacker must have WordPress administrator privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities