The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
References
Link | Resource |
---|---|
https://jetpack.com/2021/07/22/severe-vulnerability-patched-in-woocommerce-currency-switcher/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/a0bc4b13-53fe-462d-8306-8915196d3a5a/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:48:44.185Z
Updated: 2024-01-16T15:48:44.185Z
Reserved: 2021-01-14T15:03:46.770Z
Link: CVE-2021-24566
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-16T16:15:09.003
Modified: 2024-01-23T20:37:16.450
Link: CVE-2021-24566
JSON object: View
Redhat Information
No data.
CWE