CVE-2024-10857

MEDIUM EXPLOITED

Product Input Fields for WooCommerce <= 1.9 - Authenticated Path Traversal via handle_downloads()

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-10857 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Scores

CVSS v3 6.5
EPSS 0.0073
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2024-11-25
CWE
CWE-35
Status published
Products (2)
tychesoftwares/Product Input Fields for WooCommerce < 1.9
tychesoftwares/product_input_fields_for_woocommerce < 2.0
Published Nov 26, 2024
Tracked Since Feb 18, 2026