CVE-2025-6222: WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'cedrnxorderexchangeattachfiles' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet (WordPress)to a version that resolves this vulnerability.Fixed in 3.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6222?
CVE-2025-6222 is rated as a critical vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2025-6222?
To fix CVE-2025-6222, ensure that you update the WooCommerce Refund And Exchange with RMA plugin to version 3.2.7 or later.
What software is affected by CVE-2025-6222?
CVE-2025-6222 affects all versions of the WooCommerce Refund And Exchange with RMA plugin up to and including version 3.2.6.
What type of vulnerability is CVE-2025-6222?
CVE-2025-6222 is a security vulnerability that allows arbitrary file uploads due to inadequate file type validation.
Who is responsible for fixing CVE-2025-6222?
The vendor, WooCommerce, is responsible for providing updates and patches for CVE-2025-6222.