CRITICAL
WordPress Mollie Payments for WooCommerce Plugin <= 7.3.11 is vulnerable to Arbitrary File Upload
Published Feb 29, 2024
9.1
CRITICALCVSS 3.1
EPSS 0.60%
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCommerce: from n/a through 7.3.11.
Affected products
-
Affected
- ≤ 7.3.11
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mollie | Mollie Payments for WooCommerce | unaffected | Affected
|
- < 7.3.12
-
Affected
- ≥ 0, ≤ 7.3.11
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mollie | Mollie Payments for Woocommerce | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 7.3.12 or a higher version.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Feb 29, 2024
Updated Apr 28, 2026
Reserved Nov 13, 2023
Link CVE-2023-6090
CISA Vulnrichment
Updated Feb 29, 2024
Red Hat
No data
GitHub
No data