CVE-2025-13329 - File Uploader for WooCommerce <= 1.0.3 - unauthenticated arbitrary file upload v...

CVE-2025-13329 - File Uploader for WooCommerce <= 1.0.3 - unauthenticated arbitrary file upload v...

CVE ID : CVE-2025-13329 Published : Dec. 20, 2025, 4:16 a.m. | 26 minutes ago Description : The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary files to the Uploadcare service and subsequently download them on the affected site's server which may make remote code execution possible. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Dec. 20, 2025
Affected Product: WordPress
Impact: remote code execution

Source: Telegram CVE Monitor