CVE-2024-49249 HIGH

CVE-2024-49249: WordPress SMSA Shipping plugin <= 2.3 - Arbitrary File Deletion vulnerability

Vendor Smsa Express
Product SMSA Shipping
Weakness CWE-35
Published January 7, 2025
Last update April 28, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.This issue affects SMSA Shipping: from n/a through <= 2.3.

Explanation of Vulnerability in Simple Terms

02Summary

SMSA Shipping versions 2.3 and earlier contain a flaw that allows an attacker to disrupt service availability without authentication. The vulnerability requires only network access and no user interaction. The impact extends beyond the vulnerable component itself, potentially affecting dependent systems or services.

What an attacker can do

03Attacker Capabilities

Disrupt the availability of the SMSA Shipping service or dependent systems.

Potential impact on your site

04Site Impact

Service downtime or degradation affecting shipping operations and dependent integrations.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

January 7, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE