Impact
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability caused by missing file type validation in the wcap_add_to_cart_popup_upload_files function. An attacker who can authenticate as a subscriber or higher can upload any file to the site’s server, which may enable the attacker to execute code remotely or locally depending on how the server handles uploaded content.
Affected Systems
Tyche Softwares Abandoned Cart Pro for WooCommerce, all versions up to and including 9.16.0.
Risk and Exploitability
The vulnerability scores a high CVSS score of 8.8, and while the EPSS score is below 1% indicating a low probability of exploitation, it is still possible. The issue is not listed in the CISA KEV catalog. The attack requires a valid authenticated user with subscriber-level or higher privileges but no additional escalations.
OpenCVE Enrichment
EUVD