CVE-2024-10627 is a critical arbitrary file upload vulnerability affecting all versions of the WooCommerce Support Ticket System plugin for WordPress up to and including 17.7. The flaw stems from a lack of file type validation in the ajax_manage_file_chunk_upload() function, allowing unauthenticated attackers to upload malicious files. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a severe risk, potentially leading to remote code execution and complete compromise of the affected website. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 17.7CPE match | cpe:2.3:a:vanquish:woocommerce_support_ticket_system:*:*:*:*:*:wordpress:*:* | ||
< 17.8CPE matchmatch criteria | cpe:2.3:a:vanquish:woocommerce_support_ticket_system:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.