CVE-2012-3576

wpStoreCart < 2.5.30 - Unauthenticated Arbitrary File Upload and Remote Code Execution via upload.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-3576. PoCs published by Sammy FORGIT, Ydvmtzv.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in wpStoreCart WordPress plugin versions 2.5.27-2.5.29. It uses cURL to upload a malicious PHP file (lo.php) to the vulnerable endpoint, achieving remote code execution.

Description

Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Sammy FORGIT · phpwebappsphp
https://www.exploit-db.com/exploits/19023

This exploit demonstrates an arbitrary file upload vulnerability in wpStoreCart WordPress plugin versions 2.5.27-2.5.29. It uses cURL to upload a malicious PHP file (lo.php) to the vulnerable endpoint, achieving remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: wpStoreCart WordPress Plugin 2.5.27-2.5.29
No auth needed
Prerequisites: Target running vulnerable wpStoreCart plugin · Access to the upload endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Ydvmtzv · poc
https://github.com/Ydvmtzv/wpstorecart-exploit

This is a bash script that exploits an arbitrary file upload vulnerability in the wpStoreCart WordPress plugin before version 2.5.30 (CVE-2012-3576). It sends a POST request to upload a file to the vulnerable endpoint and checks for a successful response.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: wpStoreCart WordPress plugin < 2.5.30
No auth needed
Prerequisites: Target must have wpStoreCart plugin < 2.5.30 installed · Upload endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/76166
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19023
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49459

Scores

EPSS 0.1842
EPSS Percentile 96.9%

Details

CWE
CWE-264
Status published
Products (50)
jquindlen/wpstorecart 0.62
jquindlen/wpstorecart 1.0.0
jquindlen/wpstorecart 2.0.0
jquindlen/wpstorecart 2.0.1
jquindlen/wpstorecart 2.0.2
jquindlen/wpstorecart 2.0.3
jquindlen/wpstorecart 2.0.4
jquindlen/wpstorecart 2.0.5
jquindlen/wpstorecart 2.0.6
jquindlen/wpstorecart 2.0.7
... and 40 more
Published Jun 16, 2012
Tracked Since Feb 18, 2026