CVE-2025-4387
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in all versions up to, and including, 9.16.0. This makes it possible for an authenticated attacker, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may allow for either remote or local code execution depending on the server configuration.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-06-10 04:15:34
Güncelleme
2025-06-12 16:06:39
Source Identifier
security@wordfence.com
KEV Date Added
-
Kategoriler
Referanslar
https://www.tychesoftwares.com/docs/docs/abandoned-cart-pro-for-woocommerce-new/changelog-abandoned-cart-pro/#changelog-abandon-cart-pro-for-woocommerce-9-17-0-release-date-m
https://www.tychesoftwares.com/products/woocommerce-abandoned-cart-pro-plugin/
https://www.wordfence.com/threat-intel/vulnerabilities/id/5d2f07bb-89b3-41d4-b606-9722deecf816?source=cve