CVE-2025-39557

CRITICAL

Kadence WP Kadence WooCommerce Email Designer <1.5.14 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.14.

Scores

CVSS v3 9.1
EPSS 0.0038
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
Ben Ritner - Kadence WP/Kadence WooCommerce Email Designer < 1.5.14
StellarWP/Kadence WooCommerce Email Designer < 1.5.14
Published Apr 16, 2025
Tracked Since Feb 18, 2026