{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/drag-and-drop-multiple-file-upload-for-woocommerce--1.1.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:drag_and_drop_multiple_file_upload_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-4403"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Drag and Drop Multiple File Upload for WooCommerce (\u003c= 1.1.6)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","file-upload","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress (versions 1.1.6 and below) is susceptible to an unauthenticated arbitrary file upload vulnerability identified as CVE-2025-4403. The vulnerability stems from the plugin's \u003ccode\u003eupload()\u003c/code\u003e function, which fails to adequately validate the \u003ccode\u003esupported_type\u003c/code\u003e parameter or the file extension of uploaded files. By manipulating these parameters, unauthenticated remote attackers can bypass intended restrictions to upload malicious files, such as web shells, directly to the web server. Successful exploitation allows for full remote code execution (RCE) on the WordPress instance. Given the availability of public exploit scripts, the risk of exploitation is elevated for internet-facing installations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS score of 9.8. Successful exploitation leads to full system compromise, allowing an attacker to execute arbitrary code, modify site content, exfiltrate sensitive data from the WordPress database, or leverage the compromised server to conduct further attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u0026quot;Drag and Drop Multiple File Upload for WooCommerce\u0026quot; plugin to a version patched against CVE-2025-4403 immediately.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable or cannot be applied, disable the plugin until a secure version is installed.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring to detect the creation of unexpected files within the WordPress uploads directory.\u003c/li\u003e\n\u003cli\u003eConfigure web server rules to deny execution of scripts (e.g., .php files) within the upload storage directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T09:48:36Z","date_published":"2026-09-06T09:48:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-4403/","summary":"The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress versions 1.1.6 and below contains an unauthenticated arbitrary file upload vulnerability, allowing attackers to achieve remote code execution.","title":"Unauthenticated Arbitrary File Upload in Drag and Drop Multiple File Upload for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-4403/"}],"language":"en","title":"CraftedSignal Threat Feed - Drag and Drop Multiple File Upload for WooCommerce (\u003c= 1.1.6)","version":"https://jsonfeed.org/version/1.1"}