CVE-2025-4387: Abandoned Cart Pro for WooCommerce <= 9.16.0 - Authenticated (Subscriber+) Arbitrary File Upload
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcapaddtocartpopupuploadfiles function in all versions up to, and including, 9.16.0. This makes it possible for an authenticated attacker, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may allow for either remote or local code execution depending on the server configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4387?
CVE-2025-4387 is classified as a high severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2025-4387?
To mitigate CVE-2025-4387, update the Abandoned Cart Pro for WooCommerce plugin to version 9.17.0 or later.
What kind of vulnerability is CVE-2025-4387?
CVE-2025-4387 is an authenticated arbitrary file upload vulnerability caused by missing file type validation.
Which versions are affected by CVE-2025-4387?
CVE-2025-4387 affects all versions of the Abandoned Cart Pro for WooCommerce plugin up to and including 9.16.0.
Who is the vendor associated with CVE-2025-4387?
CVE-2025-4387 is associated with VillaTheme, the vendor of the Abandoned Cart Pro for WooCommerce plugin.