CVE-2024-9756

MEDIUM

Directsoftware Order Attachments For ... - Missing Authorization

Title source: rule

Description

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

Exploits (2)

nomisec WORKING POC 1 stars
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-9756
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-9756

Scores

CVSS v3 4.3
EPSS 0.0244
EPSS Percentile 85.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-862
Status published
Products (1)
directsoftware/order_attachments_for_woocommerce 2.0 - 2.5.0
Published Oct 12, 2024
Tracked Since Feb 18, 2026