CVE-2024-35658 HIGH

CVE-2024-35658: WordPress Checkout Field Editor for WooCommerce (Pro) plugin <= 3.6.2 - Unauthenticated Arbitrary File Deletion vulnerability

Vendor Themehigh
Product Checkout Field Editor for WooCommerce (Pro)
Weakness CWE-22 · Path traversal
Published June 10, 2024
Last update April 28, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through 3.6.2.

Explanation of Vulnerability in Simple Terms

02Summary

The Checkout Field Editor for WooCommerce Pro plugin through version 3.6.2 contains a path traversal vulnerability that allows unauthenticated attackers to disrupt site availability. An attacker can craft requests that cause the plugin to consume excessive resources or crash, making the site unavailable to legitimate users. No user interaction is required. Update immediately to a version newer than 3.6.2.

What an attacker can do

03Attacker Capabilities

Make your WooCommerce site unavailable by triggering resource exhaustion or crashes via path traversal requests.

Potential impact on your site

04Site Impact

Your WooCommerce checkout and site may become unavailable during an attack, disrupting sales and customer access.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 10, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE