External risk intelligence

WooCommerce Uni CPO Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10412

The vulnerability exists in a WordPress plugin designed for e-commerce product customization. Such plugins are typically installed on public-facing websites to handle customer interactions, pricing, and file uploads. Because this plugin operates as part of a public web application's storefront, it is commonly exposed to the internet.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress e-commerce plugin that allows for product options and price calculations. It could enable unauthenticated attackers to upload malicious files to the server, potentially leading to remote code execution. The main concern is to confirm if this specific plugin is in use and if so, to assess exposure.

  • Unauthenticated attackers could upload malicious files.
  • It impacts e-commerce sites using a specific WordPress plugin.
  • Confirm if this plugin is in use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can upload a malicious file to a WordPress site by targeting the Uni CPO plugin's file upload feature. This function does not properly check the type of file being uploaded, allowing an attacker to bypass security measures. Once a malicious file is uploaded, it could potentially be executed on the server, leading to remote code execution.

  • Unauthenticated access to the site.
  • Uploading a malicious file via the plugin.
  • Remote code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to upload arbitrary files to the server. When supported by the advisory, this could lead to remote code execution on the affected WordPress site.

  • Arbitrary file uploads to the server.
  • Unauthenticated file type validation flaws.
  • Potential for remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WooCommerce – Uni CPO (Premium) plugin's arbitrary file upload vulnerability necessitates action from the application owner and platform team responsible for the WordPress site. The immediate first step is to identify all instances of the plugin across the environment, assess their exposure, and confirm business criticality. Once confirmed, the accountable owner should be engaged to plan remediation, which may involve vendor coordination or temporary risk reduction measures if immediate patching is not feasible.

  • Application owners should manage this issue.
  • Verify plugin reachability and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Uni CPO plugin for WooCommerce?

Uni CPO (Premium) is a WordPress plugin that extends WooCommerce by adding advanced product options and dynamic price calculation formulas. It allows store owners to offer custom, configurable products to customers who need to select specific attributes or upload files as part of their purchase process.

What does CWE-434 mean regarding CVE-2025-10412?

CWE-434 refers to Unrestricted Upload of File with Dangerous Type. In the context of CVE-2025-10412, this means the plugin fails to properly verify or restrict the file extensions and formats being uploaded. Because the validation logic is flawed, the system blindly accepts files, including those containing malicious code that could compromise the server.

How does an attacker trigger this vulnerability?

An attacker targets the uni_cpo_upload_file function directly, bypassing standard site authentication. They do not need a valid customer account or administrative login to submit the file. Note that simply viewing a product page or browsing the store does not trigger the bug; the exploit requires specific, unauthorized interaction with the upload function.

Is my site at risk if I use Uni CPO?

Halo Surface Signal indicates that because this plugin is designed for public e-commerce storefronts to handle customer data and uploads, it is almost certainly exposed to the internet. If your site uses this plugin to process product customizations, it is likely reachable by attackers regardless of whether the site is a small shop or a large marketplace.

What are the first steps to secure my server?

Start by identifying all WordPress installations where this specific plugin is active. Once found, verify if the site is business-critical and determine its public exposure. If you cannot update the plugin to a version beyond 4.9.55 immediately, coordinate with your technical team to temporarily disable the file upload features or restrict access to the affected directory.

References