CVE-2024-3957Code Injection in FOR Woocommerce

Severity
7.3HIGHNVD
CNA6.5
EPSS
0.7%
top 28.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2

Description

The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed and what shortcode functionality they provide.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages1 packages

NVDbooster/booster< 7.1.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9w9h-rrwj-7788: The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 72024-05-02
CVEList
Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution2024-05-02
CVE-2024-3957 — Code Injection in FOR Woocommerce | cvebase