External risk intelligence

Booster for WooCommerce Arbitrary File Upload

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2024-13342

The vulnerability affects a WordPress plugin designed for WooCommerce. WooCommerce sites are commonly deployed as public-facing e-commerce storefronts accessible via the internet, making the vulnerable file upload functionality reachable by external users.

Unrestricted File Upload

Booster For Woocommerce

before 7.2.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Booster for WooCommerce plugin, a WordPress extension, allows unauthenticated attackers to upload arbitrary files. This could potentially lead to remote code execution on affected servers, depending on server configuration.

  • Unauthenticated attackers can upload unauthorized files.
  • Critical vulnerability for public-facing e-commerce sites.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can upload malicious files to a WordPress site if it uses the Booster for WooCommerce plugin. This is possible because the plugin does not properly validate file types when handling uploads. If the server is configured to execute files based on the first extension in a double-extension filename, this could lead to remote code execution.

  • No authentication required.
  • Upload file via a specific function.
  • Potential for remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to upload arbitrary files to the server, potentially leading to the execution of malicious code when certain server configurations are in place.

  • Arbitrary files could be uploaded to the server.
  • Uploads can occur via a vulnerable function.
  • This may lead to remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world remediation will likely involve WordPress site administrators, plugin managers, and potentially infrastructure teams if custom environments are used. The first practical step is to identify all WordPress sites running the Booster for WooCommerce plugin, determine their exposure and business criticality, and confirm the specific owner accountable for each instance before planning remediation.

  • Plugin owners should verify affected sites.
  • Confirm plugin reachability and criticality.
  • Plan remediation based on confirmed exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Booster for WooCommerce plugin?

Booster for WooCommerce is an extension for the WordPress content management system designed to add various functional features to e-commerce storefronts. It provides tools that help site owners manage checkout processes, order details, and product settings, effectively extending the core capabilities of the WooCommerce platform to handle specialized retail tasks.

What does CVE-2024-13342 mean for security?

This vulnerability is classified as Unrestricted Upload of File with Dangerous Type (CWE-434). It means the plugin fails to check if a file being uploaded is safe or malicious. Because the system does not properly validate file types, an attacker can upload arbitrary files, which may lead to the server executing malicious commands if it is configured to process those files.

How can an attacker trigger this vulnerability?

An unauthenticated attacker can exploit this by sending a specifically crafted request to the plugin's 'add_files_to_order' function. It is important to note that the vulnerability does not trigger on all servers; it specifically requires a server configuration that is set to execute files based on the first extension in a double-extension filename, such as 'image.php.jpg'.

Do I need to worry about this CVE if my site is internal?

Halo Surface Signal indicates that because this plugin is typically used for public-facing e-commerce storefronts, it is often accessible to the internet. While internal sites face less risk from external actors, any site with the plugin installed is theoretically susceptible if the server configuration allows the execution of uploaded files.

When should I take action for this vulnerability?

You should act immediately by identifying all instances of the plugin within your infrastructure. Prioritize confirming which sites are currently running versions 7.2.4 or older. Once identified, assign clear ownership for each site to ensure that plugin updates or necessary configuration changes are applied promptly to mitigate the risk of unauthorized file execution.

References