The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to overwrite arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Exthemes
Exthemes wooevents |
|
CPEs | cpe:2.3:a:exthemes:wooevents:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Exthemes
Exthemes wooevents |
Tue, 24 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codecanyon
Codecanyon wooevents |
|
CPEs | cpe:2.3:a:codecanyon:wooevents:*:*:*:*:*:*:*:* | |
Vendors & Products |
Codecanyon
Codecanyon wooevents |
|
Metrics |
ssvc
|
Tue, 24 Sep 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to overwrite arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | |
Title | WooEvents <= 4.1.2 - Unauthenticated Arbitrary File Overwrite | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-24T03:06:37.586Z
Updated: 2024-09-24T15:34:14.805Z
Reserved: 2024-09-10T17:55:26.109Z
Link: CVE-2024-8671
Vulnrichment
Updated: 2024-09-24T15:33:35.097Z
NVD
Status : Analyzed
Published: 2024-09-24T03:15:03.243
Modified: 2024-09-26T16:38:24.447
Link: CVE-2024-8671
Redhat
No data.