CVE-2024-10857
MEDIUM EXPLOITEDProduct Input Fields for WooCommerce <= 1.9 - Authenticated Path Traversal via handle_downloads()
Title source: llmExploitation Summary
CVE-2024-10857 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
References (2)
Core 2
Core References
Scores
CVSS v3
6.5
EPSS
0.0073
EPSS Percentile
49.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
VulnCheck KEV
2024-11-25
CWE
CWE-35
Status
published
Products (2)
tychesoftwares/Product Input Fields for WooCommerce
< 1.9
tychesoftwares/product_input_fields_for_woocommerce
< 2.0
Published
Nov 26, 2024
Tracked Since
Feb 18, 2026