CVE-2024-50525 is a critical unrestricted file upload vulnerability affecting Helloprint's WooCommerce plugin versions up to 2.0.2. This flaw allows an unauthenticated attacker to upload dangerous file types, specifically web shells, to the web server. With a CVSS score of 9.8 (Critical), this vulnerability presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploits, or significant community discussion have been observed, the ease of exploitation and high impact warrant immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.2CPE matchmatch criteria | cpe:2.3:a:helloprint:helloprint:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 2.0.4CPE match | cpe:2.3:a:helloprint:helloprint:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.