Tyche Softwares Abandoned Cart Pro for WooCommerce
cpe:2.3:a:tychesoftwares:abandoned_cart_pro_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 9.16.0
A vulnerability allowing authenticated users to upload arbitrary files has been identified in the Abandoned Cart Pro for WooCommerce plugin, in versions through 9.16.0. This vulnerability arises from inadequate file type validation in the 'wcap_add_to_cart_popup_upload_files' function. An authenticated attacker with subscriber-level access or higher could exploit this vulnerability to upload files to the server, potentially leading to remote or local code execution, depending on the server's configuration.
Exploitation of this vulnerability could result in unauthorized file uploads, with the uploaded files possibly being executed as code on the server, depending on the server's setup.
Users are advised to update the Abandoned Cart Pro for WooCommerce plugin to version 9.17.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.