CVE-2021-24212
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
Record summary
CVE-2021-24212 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 21, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WooCommerce Help Scout | CVE List | 2.9.1 to < 2.9.1 | affected |
help_scoutBrowse woocommerce / help_scout | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWooCommerce Help Scout - Arbitrary File UploadCVSS 9.8
WooCommerce Help Scout plugin before version 2.9.1 contains an unrestricted file upload vulnerability. The vulnerability allows unauthenticated users to upload arbitrary files to the server which by default will end up in wp-content/uploads/hstmp/ directory, potentially leading to remote code execution.
Impact
Unauthenticated attackers can upload malicious files, potentially leading to remote code execution or site compromise.
Remediation
Update to version 2.9.1 or later.
Source: ProjectDiscovery