Official Product Homepageproduct
https://kaimi.io/ CVE-2018-25436
CRITICAL
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload
Record summary
CVE-2018-25436 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Baggage Freight Shipping AustraliaBrowse Shipster / Baggage Freight Shipping Australia | CVE List | 0.1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File UploadExploitDB exploitby KaimiNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25436 Product Referenceproduct
https://wordpress.org/plugins/baggage-freight ExploitDB-46061exploit
https://www.exploit-db.com/exploits/46061 VulnCheck Advisory: WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File UploadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-baggage-freight-shipping-australia-arbitrary-file-upload