CVE-2025-60207: WordPress Custom User Registration Fields for WooCommerce plugin <= 2.1.2 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Custom User Registration Fields for WooCommerce: from n/a through <= 2.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60207?
CVE-2025-60207 is considered a critical vulnerability due to its potential to allow unrestricted file uploads, including web shells.
How do I fix CVE-2025-60207?
To fix CVE-2025-60207, update the Addify Custom User Registration Fields for WooCommerce plugin to version 2.1.3 or later.
What type of vulnerability is CVE-2025-60207?
CVE-2025-60207 is an Unrestricted Upload of File with Dangerous Type vulnerability.
Which software versions are affected by CVE-2025-60207?
CVE-2025-60207 affects versions of Addify Custom User Registration Fields for WooCommerce up to and including 2.1.2.
What can an attacker do using CVE-2025-60207?
An attacker can upload a web shell to the server, potentially leading to full server compromise.