WooCommerce Help Scout plugin before version 2.9.1 contains an unrestricted file upload vulnerability. The vulnerability allows unauthenticated users to upload arbitrary files to the server which by default will end up in wp-content/uploads/hstmp/ directory, potentially leading to remote code execution.
id: CVE-2021-24212
info:
name: WooCommerce Help Scout - Arbitrary File Upload
author: ritikchad
...