External risk intelligence

Custom User Registration Fields for WooCommerce Unrestricted File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-60207

The vulnerability exists in a WooCommerce plugin designed to manage user registration fields. Because this plugin is intended to be used on public-facing e-commerce websites to handle user interactions and data collection, the vulnerable file upload functionality is commonly reachable from the internet as part of the normal operation of the web storefront.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WooCommerce plugin used for user registration fields, allowing an attacker to upload a web shell to the server. While the specific impact depends on the plugin's configuration and usage, this type of vulnerability can enable unauthorized control over web servers. The main concern is confirming relevance and exposure to determine the actual risk to our systems.

  • Allows uploading malicious files to servers.
  • Enables unauthorized server control.
  • Confirm relevance and exposure to assess risk.

Attack Path

How an attacker could exploit the issue

An attacker can upload a web shell to a server by exploiting a vulnerability in the user registration fields plugin for WooCommerce. This allows them to execute arbitrary code on the server, potentially leading to full control of the website and its data.

  • Publicly accessible without authentication.
  • Uploading a dangerous file type.
  • Full server compromise possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to upload a web shell to the web server, potentially leading to the execution of arbitrary code. This could occur when the affected plugin's file upload functionality is accessible and exploited.

  • Web server file system.
  • Malicious file upload.
  • Server compromise and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Addify Custom User Registration Fields for WooCommerce plugin likely impacts e-commerce site owners and platform administrators responsible for maintaining the integrity and security of their customer-facing applications. The first practical step is to confirm if this plugin is deployed, determine its internet exposure and business criticality, identify the accountable owner, and then plan remediation based on the assessed risk.

  • Own the issue: Platform and application owners.
  • Verify first: Plugin deployment and internet exposure.
  • Action: Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Custom User Registration Fields for WooCommerce plugin?

This is a WordPress plugin by Addify used by e-commerce store owners to expand the standard checkout or signup process. It allows administrators to add custom data entry fields—such as text boxes or file uploaders—to user profiles or registration forms, helping businesses collect specific customer information during account creation.

What does CWE-434 mean for CVE-2025-60207?

CWE-434 refers to 'Unrestricted Upload of File with Dangerous Type.' In this CVE, it means the plugin fails to properly verify or limit the types of files users are allowed to upload. Because the plugin does not enforce strict enough checks, an attacker can bypass security to upload a web shell, which is a script that gives them the ability to run commands directly on your web server.

Does this vulnerability require a user to be logged in?

No, this vulnerability does not require authentication. An attacker can attempt to trigger this bug remotely without needing an existing account on the website. However, the flaw specifically targets the plugin's file upload functionality; if your site configuration does not use or has explicitly disabled file uploads within this specific plugin, the path for this particular exploit may not exist.

Why does Halo Surface Signal categorize this as likely relevant?

Halo Surface Signal identifies this as likely relevant because the affected plugin is designed to power registration forms on public-facing e-commerce storefronts. Since these sites are intentionally built to accept traffic and user submissions from the internet, the vulnerable component is often directly reachable, creating an accessible path for an attacker to reach the file upload feature.

How do I address this plugin vulnerability?

Start by identifying if your WordPress site is currently running this specific Addify plugin. If it is, determine its visibility to the public and its importance to your business operations. Work with your platform administrators to locate the plugin's owner, assess the risk to your environment, and coordinate a plan to update the software or remove the component if it is not strictly necessary for your storefront.