CVE-2024-50494

CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Upload a Web Shell to a Web Server.This issue affect...

Affects 0 products across 2 vendors.

BCS7.54
CVSS 3.110.0
EPSS0.5%
Percentile40th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the Sudan Payment Gateway for WooCommerce plugin allows attackers to upload a web shell to the web server, potentially leading to full server compromise.

BSID: BS-2024-GLOBAL-218967-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-50494?
A critical vulnerability in the Sudan Payment Gateway for WooCommerce plugin allows attackers to upload a web shell to the web server, potentially leading to full server compromise.
What is the CVSS score for CVE-2024-50494?
CVE-2024-50494 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2024-50494 actively exploited?
No confirmed active exploitation of CVE-2024-50494 as of 2026-05-30.
How do I remediate CVE-2024-50494?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-50494?
CVE-2024-50494 affects: Gateway, Woocommerce.
Vulnerability Details
CVE IDCVE-2024-50494
BSIDBS-2024-GLOBAL-218967-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-10-29
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Upload a Web Shell to a Web Server.This issue affects Sudan Payment Gateway for WooCommerce: from n/a through <= 1.2.2.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability stems from the lack of proper file type validation during the file upload process, enabling attackers to upload malicious files such as web shells.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Gateway &mdash;
Woocommerce &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 644 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash9a8517ab20f806b93a8292b9fa272d014eb0a15b6ef710e769c5a7501538dacfcad2ace33d1f0b7ab4ca08f0476bd2c03cbf8089bbaa3c7231aafb6243b9c8ef
Related CVEs affecting Gateway
CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-58083 10.0 General Industrial Controls Lynx+ Gateway  is missing critical authenticatio... CVE-2002-1440 10.0 The Gateway GS-400 server has a default root password of "0001n" that can not... CVE-2026-32621 9.9 Apollo Federation is an architecture for declaratively composing APIs into a ... CVE-2026-1868 9.9 GitLab has remediated a vulnerability in the Duo Workflow Service component o...
View all Gateway CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →