Input validation vulnerability in WooCommerce Amazon Affiliates 9.0.2.16

The WooCommerce Amazon Affiliates plugin for WordPress is vulnerable to attack due to a lack of file type validation in its validate_connection function. This vulnerability affects versions of the plugin before 9.0.2.16 and could allow unauthenticated attackers to upload any type of file on the server, possibly allowing them to execute code remotely.

Detected in:

WooCommerce Amazon Affiliates fixed vulnerable versions: >= * < 9.0.2.16

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.