CVE-2024-10857

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tychesoftwares:product_input_fields_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

09 Jul 2025, 18:47

Type Values Removed Values Added
First Time Tychesoftwares
Tychesoftwares product Input Fields For Woocommerce
CPE cpe:2.3:a:tychesoftwares:product_input_fields_for_woocommerce:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/changeset/3195423/product-input-fields-for-woocommerce/trunk?contextall=1&old=3173573&old_path=%2Fproduct-input-fields-for-woocommerce%2Ftrunk - () https://plugins.trac.wordpress.org/changeset/3195423/product-input-fields-for-woocommerce/trunk?contextall=1&old=3173573&old_path=%2Fproduct-input-fields-for-woocommerce%2Ftrunk - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/e45207af-3886-4d95-9cd8-5ecdc683dc58?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/e45207af-3886-4d95-9cd8-5ecdc683dc58?source=cve - Third Party Advisory

26 Nov 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-26 07:15

Updated : 2025-07-09 18:47


NVD link : CVE-2024-10857

Mitre link : CVE-2024-10857

CVE.ORG link : CVE-2024-10857


JSON object : View

Products Affected

tychesoftwares

  • product_input_fields_for_woocommerce
CWE
CWE-35

Path Traversal: '.../...//'