CVE-2025-4403: Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supportedtype string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4403?
CVE-2025-4403 has a high severity rating due to its potential for arbitrary file uploads.
How do I fix CVE-2025-4403?
To fix CVE-2025-4403, update the Drag and Drop Multiple File Upload for WooCommerce plugin to version 1.1.7 or later.
Which versions are affected by CVE-2025-4403?
All versions of the Drag and Drop Multiple File Upload for WooCommerce plugin up to and including 1.1.6 are affected by CVE-2025-4403.
What kind of attack does CVE-2025-4403 enable?
CVE-2025-4403 enables attackers to upload arbitrary files, which can lead to code execution and server compromise.
Is there a known exploit for CVE-2025-4403?
While there may not be a publicly known exploit for CVE-2025-4403, the vulnerability itself poses a significant security risk.