<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Drag and Drop Multiple File Upload for WooCommerce (&lt;= 1.1.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/drag-and-drop-multiple-file-upload-for-woocommerce--1.1.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 06 Sep 2026 09:48:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/drag-and-drop-multiple-file-upload-for-woocommerce--1.1.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary File Upload in Drag and Drop Multiple File Upload for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2025-4403/</link><pubDate>Sun, 06 Sep 2026 09:48:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2025-4403/</guid><description>The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress versions 1.1.6 and below contains an unauthenticated arbitrary file upload vulnerability, allowing attackers to achieve remote code execution.</description><content:encoded><![CDATA[<p>The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress (versions 1.1.6 and below) is susceptible to an unauthenticated arbitrary file upload vulnerability identified as CVE-2025-4403. The vulnerability stems from the plugin's <code>upload()</code> function, which fails to adequately validate the <code>supported_type</code> parameter or the file extension of uploaded files. By manipulating these parameters, unauthenticated remote attackers can bypass intended restrictions to upload malicious files, such as web shells, directly to the web server. Successful exploitation allows for full remote code execution (RCE) on the WordPress instance. Given the availability of public exploit scripts, the risk of exploitation is elevated for internet-facing installations.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS score of 9.8. Successful exploitation leads to full system compromise, allowing an attacker to execute arbitrary code, modify site content, exfiltrate sensitive data from the WordPress database, or leverage the compromised server to conduct further attacks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the &quot;Drag and Drop Multiple File Upload for WooCommerce&quot; plugin to a version patched against CVE-2025-4403 immediately.</li>
<li>If a patch is unavailable or cannot be applied, disable the plugin until a secure version is installed.</li>
<li>Implement file integrity monitoring to detect the creation of unexpected files within the WordPress uploads directory.</li>
<li>Configure web server rules to deny execution of scripts (e.g., .php files) within the upload storage directory.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>file-upload</category><category>rce</category><category>vulnerability</category></item></channel></rss>