CVE-2024-10486
Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File
Record summary
CVE-2024-10486 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 19, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
woocommerceBrowse automattic / woocommerceDefault status: unaffected | CVE List | Through 2.8.6 | affected |
Google for WooCommerceBrowse woocommerce / Google for WooCommerceDefault status: unaffected | CVE List | Through 2.8.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGoogle for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info FileCVSS 5.3
The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.
Impact
Unauthenticated attackers can access PHP configuration information including server details, installed extensions, and environment variables, which can aid in planning further attacks.
Remediation
Update Google for WooCommerce plugin to version 2.8.7 or later.
Source: ProjectDiscovery