Impact
The MIPL Grouped Checkout Fields for WooCommerce plugin contains a flaw in the mipl_wc_upload_file function where file type validation is omitted. This omission permits any visitor to upload a file of any type to the site’s server. The uploaded file can contain malicious code, potentially allowing an attacker to execute code on the server, compromise confidentiality, integrity, and availability of the site, and possibly pivot to other systems. The weakness corresponds to CWE-434, File Upload with Dangerous File Types.
Affected Systems
WordPress sites that have the MIPL Grouped Checkout Fields for WooCommerce plugin installed with version 1.2.1 or earlier are impacted. The affected vendor is mulika, and the plugin offers a Configure & Organize Checkout Fields feature.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. Because the vulnerability is exploitable by unauthenticated users through the web interface, an attacker does not need special permissions to upload a file. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, but the lack of mitigation and high severity suggest a high likelihood of exploitation, especially on public-facing sites.
OpenCVE Enrichment