CVE-2025-39557: WordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.14.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39557?
CVE-2025-39557 is classified as a critical vulnerability due to its potential to allow unauthorized file uploads, including web shells.
How do I fix CVE-2025-39557?
To fix CVE-2025-39557, upgrade Kadence WooCommerce Email Designer to version 1.5.15 or later.
What are the implications of CVE-2025-39557?
CVE-2025-39557 allows attackers to upload malicious files, which can lead to full server compromise.
Which versions are affected by CVE-2025-39557?
CVE-2025-39557 affects Kadence WooCommerce Email Designer versions prior to 1.5.15.
Who is the vendor of the software affected by CVE-2025-39557?
The vendor of the affected software is Kadence, specifically for the Kadence WooCommerce Email Designer plugin.