HIGH🇵🇱 Wersja polska

CVE-2024-13342

CVSS 8.1v3.1pub. 2025-08-29upd. 2025-12-08

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Booster For Woocommerce

    APP
    Booster
    < 7.2.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2021-34646CRITICAL9.8PL ✓same product

Authentication bypass w pluginie Booster for WooCommerce (WordPress)

CVE-2025-64196HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2025-39446HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2024-13708HIGH7.2same product

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...

CVE-2024-13744HIGH8.1same product

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...