External risk intelligence

WooCommerce Support Ticket System Unrestricted File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-60235

This vulnerability affects a WordPress plugin designed for customer support ticketing. Such plugins are intentionally deployed to be public-facing to allow customers to submit tickets via web interfaces, making the attack surface commonly internet-accessible by design.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses an unrestricted file upload vulnerability in a WooCommerce plugin. While the specific impact depends on the plugin's configuration and usage, such issues can potentially lead to unauthorized access or control over the affected system by allowing the upload of malicious files. The main concern is confirming whether this plugin is in use and exposed to the internet.

  • Allows malicious file uploads.
  • Affects customer support interactions.
  • Confirm if the system is in use.

Attack Path

How an attacker could exploit the issue

An attacker could upload a malicious file through the Support Ticket System for WooCommerce's interface. This allows them to potentially execute arbitrary code on the server, leading to a full compromise of the affected system. The vulnerability is present in versions up to and including 2.0.7.

  • No authentication or special privileges needed.
  • Upload a malicious file via ticket system.
  • Complete server compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to upload malicious files to the system when supported by the advisory. This may impact system integrity and the availability of services.

  • System files could be affected.
  • Malicious files may be uploaded.
  • Service integrity and availability could be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WooCommerce Support Ticket System plugin is intentionally public-facing, making it accessible to external attackers. The first practical step is to identify all instances of this plugin within your WooCommerce environment, confirm if they are exposed to the internet, and determine their business criticality. Once identified and prioritized, engage the WooCommerce administrator or the team responsible for managing this plugin to plan and execute remediation.

  • WooCommerce administrators own the issue.
  • Verify internet exposure and business criticality.
  • Plan remediation during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Support Ticket System for WooCommerce plugin?

This software is a WordPress extension designed to manage customer service requests directly within a WooCommerce store. It typically adds interfaces to your website where shoppers can submit inquiries, attach files, and track support history, serving as a bridge between customers and store administrators.

What does CWE-434 mean regarding CVE-2025-60235?

CWE-434 stands for Unrestricted Upload of File with Dangerous Type. In this context, it means the plugin fails to properly validate the format or content of files uploaded through the ticket system. An attacker can exploit this weakness to save malicious scripts or programs onto the server, which could then be executed to compromise the entire system.

How do attackers trigger this vulnerability?

An attacker triggers this by interacting with the ticket submission interface provided by the plugin. They do not need to be logged into your site, nor do they require special administrative permissions to perform the upload. Simply accessing the public ticket form is sufficient to attempt the file upload; legitimate usage of the plugin for standard text-based tickets without attachments does not inherently trigger this flaw.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your risk is elevated because the software is designed to be internet-facing. Halo Surface Signal identifies that this plugin must be accessible to customers to function, which means the vulnerability is reachable by anyone on the internet. Because the ticket system acts as a public entry point, it provides a direct path for remote attackers to interact with your server.

What is the first step for someone running this technology?

Start by auditing your WordPress site to verify if the Support Ticket System for WooCommerce plugin is installed and active. Determine which versions are currently running to see if they fall within the affected range (up to 2.0.7). Once identified, consult with your site administrator to assess the business impact and prioritize moving the plugin to a secure state, such as updating it or disabling the ticket submission interface until a verified patch is applied.

References