Description
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in all versions up to, and including, 9.16.0. This makes it possible for an authenticated attacker, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may allow for either remote or local code execution depending on the server configuration.
Published: 2025-06-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file upload with potential code execution
Action: Apply Patch
AI Analysis

Impact

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability caused by missing file type validation in the wcap_add_to_cart_popup_upload_files function. An attacker who can authenticate as a subscriber or higher can upload any file to the site’s server, which may enable the attacker to execute code remotely or locally depending on how the server handles uploaded content.

Affected Systems

Tyche Softwares Abandoned Cart Pro for WooCommerce, all versions up to and including 9.16.0.

Risk and Exploitability

The vulnerability scores a high CVSS score of 8.8, and while the EPSS score is below 1% indicating a low probability of exploitation, it is still possible. The issue is not listed in the CISA KEV catalog. The attack requires a valid authenticated user with subscriber-level or higher privileges but no additional escalations.

Generated by OpenCVE AI on April 21, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin update 9.17.0 or newer, which includes the file type validation fix.
  • If an immediate update is not possible, disable or protect the file upload endpoint for subscriber and higher roles via role-based access control or by blocking the endpoint.
  • Implement a server‑side file type validation layer or use a WAF to reject unauthorized file uploads and verify mime types before allowing storage.

Generated by OpenCVE AI on April 21, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17622 The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in all versions up to, and including, 9.16.0. This makes it possible for an authenticated attacker, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may allow for either remote or local code execution depending on the server configuration.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00062}

epss

{'score': 0.00071}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 04:00:00 +0000

Type Values Removed Values Added
Description The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in all versions up to, and including, 9.16.0. This makes it possible for an authenticated attacker, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may allow for either remote or local code execution depending on the server configuration.
Title Abandoned Cart Pro for WooCommerce <= 9.16.0 - Authenticated (Subscriber+) Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:55:47.915Z

Reserved: 2025-05-06T17:02:27.568Z

Link: CVE-2025-4387

cve-icon Vulnrichment

Updated: 2025-06-10T14:09:57.803Z

cve-icon NVD

Status : Deferred

Published: 2025-06-10T04:15:34.623

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-4387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T20:30:27Z

Weaknesses