Record summary

CVE-2018-25436 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File UploadExploitDB exploitby KaimiNot analyzed1 file
ExploitDB

PoC details

References

5