CVE-2025-29009: WordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through 1.2.3.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <= 1.2.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29009?
CVE-2025-29009 has a high severity rating due to the potential for unrestricted file uploads allowing web shell access.
How do I fix CVE-2025-29009?
To fix CVE-2025-29009, update the Webkul Medical Prescription Attachment Plugin for WooCommerce to version 1.2.4 or later.
What versions are affected by CVE-2025-29009?
CVE-2025-29009 affects all versions of the Medical Prescription Attachment Plugin for WooCommerce up to and including version 1.2.3.
What type of vulnerability is CVE-2025-29009?
CVE-2025-29009 is classified as an Unrestricted File Upload vulnerability which can lead to remote code execution.
Who is affected by CVE-2025-29009?
Users of the Medical Prescription Attachment Plugin for WooCommerce version 1.2.3 or earlier are at risk due to CVE-2025-29009.