Appsecure logo

CVE-2025-2941: Critical Vulnerability in Drag and Drop Multiple File Upload for WooCommerce Plugin

A critical vulnerability in the Drag and Drop Multiple File Upload for WooCommerce plugin allows unauthenticated attackers to move arbitrary files on the server. This could potentially lead to remote code execution. Immediate action is required to mitigate risks associated with this flaw.

CRITICALCVSS 9.8 · Published April 5, 2025

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2025-2941 is classified as a critical vulnerability with a CVSS score of 9.8. The vulnerability resides in the Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress and allows unauthenticated attackers to exploit insufficient file path validation through the wc-upload-file[] parameter. This could lead to arbitrary file movement on the server, posing a severe risk of remote code execution, particularly if sensitive files like wp-config.php are manipulated.

The implications of this vulnerability are significant. Attackers may leverage this flaw to execute arbitrary code, potentially compromising the entire application and the underlying server. Given the ease of exploitation due to the lack of required privileges or user interaction, organizations utilizing this plugin must act swiftly.

Risk to organizations includes unauthorized access to sensitive data, complete system compromise, and potential disruption of services. Organizations should prioritize patching immediately to defend against potential exploitation. As of the latest updates, there are no known exploits or proofs of concept available publicly, but the critical nature of this vulnerability necessitates immediate attention.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.