← WordPress Vulnerabilities
WordPress security by component

InPost for WooCommerce plugin and InPost PL

InPost for WooCommerce plugin and InPost PL is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 17, 2024; the highest CVE/CNA score is 10.

Plugin slug: inpost-for-woocommerce

CVE-2024-6500: InPost for WooCommerce plugin and InPost PL: Arbitrary file deletion

InPost for WooCommerce plugin and InPost PL is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable.

PublishedAug 17, 2024
Safe version guidanceSee mitigation notes
Safe version
Aug 17, 2024 CVE-2024-6500
InPost for WooCommerce plugin and InPost PL: Arbitrary file deletion
InPost for WooCommerce plugin and InPost PL is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVE10.0
NVDPending