CVE-2024-6500

CRITICAL

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in ...

Affects 0 products across 6 vendors.

BCS7.77
CVSS 3.110.0
EPSS1.0%
Percentile59th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-862: Missing Authorization

Software does not check whether an authenticated actor has permission for the requested operation.

Related Attack Patterns (CAPEC)
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-862

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check.

BSID: BS-2024-GLOBAL-047528-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-6500?
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check.
What is the CVSS score for CVE-2024-6500?
CVE-2024-6500 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H. EPSS: 1.0%.
Is CVE-2024-6500 actively exploited?
No confirmed active exploitation of CVE-2024-6500 as of 2026-05-30.
How do I remediate CVE-2024-6500?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-6500?
CVE-2024-6500 affects: Files, Linux, Plugin, Windows, Woocommerce, Wordpress.
Vulnerability Details
CVE IDCVE-2024-6500
BSIDBS-2024-GLOBAL-047528-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Published2024-08-17
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL). This makes it possible for unauthenticated attackers to read and delete arbitrary files on Windows servers. On Linux servers, only files within the WordPress install will be deleted, but all files can be read.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Unauthenticated attackers can exploit a missing capability check on the 'parse_request' function to read and delete arbitrary files on Windows systems.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Files —
Linux —
Plugin —
Windows —
Woocommerce —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 720 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashfc4a89295956cb91b9181622e8c263d1c5b0912d20ff43f1a4e03b5a697af37898eaf9afe429a566a02e048adff47a9e1f7c672b0b20955081439a27fb590837
Related CVEs affecting Files
CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-2026-34909 10.0 A malicious actor with access to the network could exploit a Path Traversal v... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →