The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to overwrite arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Exthemes
Exthemes wooevents |
|
CPEs | cpe:2.3:a:exthemes:wooevents:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Exthemes
Exthemes wooevents |
Tue, 24 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codecanyon
Codecanyon wooevents |
|
CPEs | cpe:2.3:a:codecanyon:wooevents:*:*:*:*:*:*:*:* | |
Vendors & Products |
Codecanyon
Codecanyon wooevents |
|
Metrics |
ssvc
|
Tue, 24 Sep 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to overwrite arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | |
Title | WooEvents <= 4.1.2 - Unauthenticated Arbitrary File Overwrite | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-09-24T15:34:14.805Z
Reserved: 2024-09-10T17:55:26.109Z
Link: CVE-2024-8671

Updated: 2024-09-24T15:33:35.097Z

Status : Analyzed
Published: 2024-09-24T03:15:03.243
Modified: 2024-09-26T16:38:24.447
Link: CVE-2024-8671

No data.