Back to overview

CVE-2024-6500

CRITICAL
10.0
CVSS 3.1
Description
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL). This makes it possible for unauthenticated attackers to read and delete arbitrary files on Windows servers. On Linux servers, only files within the WordPress install will be deleted, but all files can be read.

Metadata

CVE ID
CVE-2024-6500
State
PUBLISHED
Assigner
Wordfence
Reserved
2024-07-04 00:24 UTC
Published
2024-08-17 02:31 UTC
Last updated
2026-04-08 17:02 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
inspirelabs / InPost for WooCommerce
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
inspirelabs InPost for WooCommerce 0 ≤ 1.4.0
inspirelabs InPost PL 0 ≤ 1.4.4
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Back to overview