Record summary

CVE-2024-10486 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 19, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 2.8.6affected

Default status: unaffected

CVE ListThrough 2.8.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGoogle for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info FileCVSS 5.3

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.

Impact

Unauthenticated attackers can access PHP configuration information including server details, installed extensions, and environment variables, which can aid in planning further attacks.

Remediation

Update Google for WooCommerce plugin to version 2.8.7 or later.

WeaknessesCWE-862
Authorspopcorn94
Template tagscvecve2024wpwordpresswp-plugingoogle-listings-and-adsinfo-leakvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Source: ProjectDiscovery

References

3