External risk intelligence

WooCommerce Product Addons Plugin Arbitrary File Upload Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-11391

The vulnerability exists in a WooCommerce plugin for WordPress. WordPress sites, especially those utilizing e-commerce functionality, are designed to be public-facing web applications. The vulnerable functionality is accessible to unauthenticated users, making the attack surface an exposed, public-facing web endpoint by default.

Unrestricted File Upload

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical security vulnerability within a WordPress e-commerce plugin. The flaw allows unauthenticated attackers to upload malicious files, potentially leading to unauthorized code execution on the server. This could impact the integrity and availability of affected e-commerce operations.

  • Unauthenticated file uploads can compromise sites.
  • Critical vulnerability in a popular e-commerce plugin.
  • Confirm relevance and exposure of the plugin.

Attack Path

How an attacker could exploit the issue

An attacker can upload arbitrary files to a WordPress site by exploiting a flaw in the WooCommerce plugin's image cropping feature. This vulnerability does not require the attacker to log in and can lead to the execution of malicious code on the server, especially when the paid version of the plugin is installed.

  • Attacker can exploit without authentication.
  • Vulnerable component is image cropper.
  • Risk includes remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload arbitrary files to the server of a WordPress site running a specific WooCommerce add-on. This could potentially lead to remote code execution, affecting the integrity and availability of the affected website.

  • Server files could be compromised.
  • Arbitrary files may be uploaded.
  • Remote code execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that the vulnerability is in a WordPress plugin utilized by the paid version of WooCommerce, the platform team responsible for managing the WordPress instance and the application owner of the WooCommerce store are likely responsible for remediation. The initial step is to locate all instances of the affected plugin, confirm business criticality and reachability, and then engage the accountable owner to plan the necessary actions.

  • Platform and application owners must address.
  • Verify plugin presence and reachability.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the PPOM – Product Addons & Custom Fields for WooCommerce plugin?

This is a WordPress plugin designed to extend the core functionality of WooCommerce. It allows store owners to add custom input fields and product personalization options, such as custom text boxes or image uploads, to their e-commerce storefronts.

What does CWE-434 mean regarding CVE-2025-11391?

CWE-434 refers to Unrestricted Upload of File with Dangerous Type. In this CVE, it means the software's image cropper tool lacks proper checks to verify that uploaded files are actually safe images, allowing attackers to upload malicious scripts instead.

How can an attacker trigger this vulnerability?

An attacker triggers this by interacting with the image cropper functionality within the plugin. Crucially, they do not need to be logged in to do this. However, the vulnerability specifically impacts sites where the paid version of this software is active.

Is my site at risk if I run this plugin?

Because the plugin is designed for e-commerce, Halo Surface Signal notes these sites are typically public-facing web applications. Since the vulnerable endpoint is accessible to unauthenticated users, any internet-facing WordPress site using the paid version is potentially reachable by attackers.

When should I take action for this vulnerability?

You should act immediately by identifying if your WordPress instance has this specific plugin installed and active. Verify if your version is 33.0.15 or older, and coordinate with your application owners to prioritize updates or mitigations to secure your server.

References