nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13744 CVE-2024-13744
HIGH
Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2024-13744 has a selected CVSS score of 8.1 (high).
Description
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
booster_for_woocommerceBrowse booster / booster_for_woocommerce | VulnCheck | Version data not supplied | |
Booster for WooCommerceBrowse pluggabl / Booster for WooCommerceDefault status: unaffected | CVE List | 4.0.1 to ≤ 7.2.4 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3262569/woocommerce-jetpack/trunk/includes/input-fields/class-wcj-product-input-fields-core.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/f8e1aca8-3d82-4b1a-98c8-29501a377846?source=cve