CVE-2025-4403

CRITICAL

WooCommerce 1.1.6 - RCE

Title source: llm

Description

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Exploits (1)

nomisec WORKING POC 3 stars
by Yucaerin · poc
https://github.com/Yucaerin/CVE-2025-4403

Scores

CVSS v3 9.8
EPSS 0.0284
EPSS Percentile 86.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
glenwpcoder/Drag and Drop Multiple File Upload for WooCommerce < 1.1.6
Published May 09, 2025
Tracked Since Feb 18, 2026