File Uploader for WooCommerce <= 1.0.4 - Unauthenticated Path Traversal
medium
The File Uploader for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to perform actions on files outside of the originally intended directory.
- CVSS:
- 5.3
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 23, 2026
CVE-2026-25397 on NVD →
File Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data
critical
The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary fil...
- CVSS:
- 9.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Dec 19, 2025
CVE-2025-13329 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database