CVE Vulnerabilities

CVE-2024-6000

Published: Jun 15, 2024 | Modified: Jun 15, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the display_ticket_themes_page function in versions up to, and including, 1.19.20. This makes it possible for authenticated attackers with contributor-level capabilities or above, to upload arbitrary files on the affected sites server which may make remote code execution possible. This was partially patched in 1.19.20, and fully patched in 1.19.21.

References