Record summary

CVE-2024-25925 has a selected CVSS score of 10.0 (critical).

Description

Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 3, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WooCommerce Easy Checkout Field Editor, Fees & Discounts

Browse SYSBASICS / WooCommerce Easy Checkout Field Editor, Fees & Discounts

Default status: unaffected

CVE List, VulnCheckThrough 3.5.12affected

woocommerce_easy_checkout_field_editor

Browse sysbasics / woocommerce_easy_checkout_field_editor

Default status: unaffected

CVE ListThrough 3.5.12affected

References

2