CVE-2018-25436

CRITICAL

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25436. PoCs published by Kaimi.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the WordPress Baggage Freight Shipping Australia plugin (0.1.0). The vulnerable code in upload-package.php lacks file extension validation, allowing unauthenticated attackers to upload malicious PHP files.

Description

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.

Exploits (1)

exploitdb WORKING POC
by Kaimi · textwebappsphp
https://www.exploit-db.com/exploits/46061

This exploit demonstrates an arbitrary file upload vulnerability in the WordPress Baggage Freight Shipping Australia plugin (0.1.0). The vulnerable code in upload-package.php lacks file extension validation, allowing unauthenticated attackers to upload malicious PHP files.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Baggage Freight Shipping Australia 0.1.0
No auth needed
Prerequisites: Access to the target WordPress site · Plugin installed and active
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46061
https://www.exploit-db.com/exploits/46061
Product product
Official Product Homepage
https://kaimi.io
Product product
Product Reference
https://wordpress.org/plugins/baggage-freight/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload
https://www.vulncheck.com/advisories/wordpress-plugin-baggage-freight-shipping-australia-arbitrary-file-upload

Scores

CVSS v3 9.8
EPSS 0.0066
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Shipster/Baggage Freight Shipping Australia 0.1.0
Published Jun 15, 2026
Tracked Since Jun 15, 2026