CVE-2025-2941: Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2941?
CVE-2025-2941 is rated as a high severity vulnerability due to its potential for arbitrary file movement.
How do I fix CVE-2025-2941?
To fix CVE-2025-2941, update the Drag and Drop Multiple File Upload for WooCommerce plugin to version 1.1.5 or later.
Who is affected by CVE-2025-2941?
Any user of the Drag and Drop Multiple File Upload for WooCommerce plugin in versions up to and including 1.1.4 is affected by CVE-2025-2941.
What type of vulnerability is CVE-2025-2941?
CVE-2025-2941 is an arbitrary file moving vulnerability resulting from insufficient file path validation.
Can CVE-2025-2941 be exploited by unauthenticated users?
Yes, CVE-2025-2941 can be exploited by unauthenticated users, making it a severe security risk.