CVE-2025-9216: StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9216?
CVE-2025-9216 has a high severity rating due to its potential for arbitrary file uploads.
How do I fix CVE-2025-9216?
To fix CVE-2025-9216, update the StoreEngine plugin to version 1.5.1 or later where the vulnerability is patched.
What systems are affected by CVE-2025-9216?
CVE-2025-9216 affects all versions of the StoreEngine plugin up to and including version 1.5.0.
What are the risks associated with CVE-2025-9216?
The risks of CVE-2025-9216 include unauthorized file uploads, which could lead to data breaches or malware installation.
Can CVE-2025-9216 be exploited remotely?
Yes, CVE-2025-9216 can be exploited remotely if the attacker has access to utilize the vulnerable import() function.