CVE-2025-6440
CRITICAL EXPLOITEDWooCommerce Designer Pro <1.9.26 - RCE
Title source: llmDescription
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Exploits (10)
github
WORKING POC
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-6440
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-6440
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
56.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-10-24
CWE
CWE-434
Status
published
Products (1)
JMA Plugins/WooCommerce Designer Pro
< 1.9.26
Published
Oct 24, 2025
Tracked Since
Feb 18, 2026