HIGH🇵🇱 Wersja polska

CVE-2024-13744

CVSS 8.1v3.1pub. 2025-04-04upd. 2025-04-09

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Booster For Woocommerce

    APP
    Booster
    4.0.1 – 7.2.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2021-34646CRITICAL9.8PL ✓same product

Authentication bypass w pluginie Booster for WooCommerce (WordPress)

CVE-2025-64196HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2024-13342HIGH8.1same product

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...

CVE-2025-39446HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2024-13708HIGH7.2same product

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...