CVE-2024-6000 Information
Description
The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the ‘display_ticket_themes_page’ function in versions up to and including 1.19.20. This makes it possible for authenticated attackers with contributor-level capabilities or above to upload arbitrary files on the affected site’s server which may make remote code execution possible. This was partially patched in 1.19.20 and fully patched in 1.19.21.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/1080810b-ec9a-44fb-b4da-49b28646a441?source=cve https://help.fooevents.com/docs/topics/changelogs/fooevents-for-woocommerce/
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.1
Share on: