CVE-2025-9216

HIGH

StoreEngine < 1.5.0 - Authenticated Arbitrary File Upload via CSV Import Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-9216. PoCs published by d0n601.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-9216, demonstrating an authenticated arbitrary file upload vulnerability in the StoreEngine WordPress plugin. The exploit leverages exposed nonces and lacks proper file validation to upload a PHP web shell, enabling remote code execution.

Description

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Exploits (1)

nomisec WORKING POC
by d0n601 · poc
https://github.com/d0n601/CVE-2025-9216

This repository contains a functional exploit for CVE-2025-9216, demonstrating an authenticated arbitrary file upload vulnerability in the StoreEngine WordPress plugin. The exploit leverages exposed nonces and lacks proper file validation to upload a PHP web shell, enabling remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: StoreEngine WordPress Plugin <= 1.4.0
Auth required
Prerequisites: Authenticated WordPress user (subscriber or higher) · CSV Import/Export addon enabled by administrator
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0082
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
kodezen/StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More < 1.5.0
kodezen/StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More < 1.5.0
Published Sep 17, 2025
Tracked Since Feb 18, 2026