WooCommerce Help Scout <= 2.9.1 - Arbitrary File Upload to Remote Code Execution

2021-03-21 00:00
Ville Korhonen / Seravo

Strategic Overview

Status
Patched in 2.9.2
Affected PluginWooCommerce Help Scout
Affected Version<= 2.9.1
CVSS9.8Critical
CVECVE-2021-24212
View all WooCommerce Help Scout vulnerabilities

Vulnerability Overview

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

Technical Analysis

REMEDIATION: Update to version 2.9.2, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C