External risk intelligence

WooCommerce Designer Pro Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-6440

The vulnerability exists in a WordPress plugin used for web design and e-commerce functionality. Such plugins are typically installed on public-facing web servers to facilitate interactions with site visitors and customers, making the vulnerable endpoint reachable via the public internet as part of standard website operation.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WordPress plugin that allows for the creation and customization of designs, which is used within a specific e-commerce theme. This flaw could enable unauthorized individuals to upload malicious files to a website's server, potentially leading to system compromise.

  • Allows file uploads to website servers.
  • Compromise could lead to remote code execution.
  • Confirm relevance and check for exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by uploading arbitrary files to the server. This is possible because the affected plugin does not properly validate file types when saving design elements. Successful exploitation could allow an attacker to execute arbitrary code on the server.

  • No authentication required.
  • Uploading a malicious file.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could upload arbitrary files to the server when the WooCommerce Designer Pro plugin is present. This may enable remote code execution under certain conditions.

  • Arbitrary files could be uploaded.
  • Via a vulnerable plugin function.
  • Server compromise and remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

This critical vulnerability in the WooCommerce Designer Pro plugin, often integrated with themes like Pricom, is likely to impact website owners and administrators responsible for e-commerce and design functionalities. The first practical step is for these teams to identify all instances of the affected plugin and theme, verify internet reachability and business criticality, and then determine the accountable owner for remediation planning.

  • Website owners and administrators should own the issue.
  • Verify plugin and theme installation and reachability.
  • Plan vendor coordination or remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WooCommerce Designer Pro plugin?

It is a WordPress extension designed for creating and customizing visual assets, such as business cards or flyers. It is commonly integrated into the Pricom Printing Company & Design Services theme to enable e-commerce design workflows directly on a WordPress site.

What does CWE-434 mean for CVE-2025-6440?

CWE-434 is the weakness class for unrestricted upload of files with a dangerous type. In this CVE, the plugin fails to check what kind of file is being saved via its canvas design function, allowing any file format to be stored on the server.

How does an attacker trigger this vulnerability?

An attacker interacts with the wcdp_save_canvas_design_ajax function to upload a file. Because the plugin lacks validation, the system accepts malicious files without requiring the attacker to log in. Simply browsing the site or using legitimate design features does not trigger this flaw.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal notes that since this plugin powers public-facing e-commerce and design tools, the vulnerable endpoint is likely reachable over the internet. If your site uses this plugin, it is considered externally accessible by design.

What should I do if I use this plugin?

Begin by auditing your WordPress environment to confirm if the WooCommerce Designer Pro plugin is installed. Once located, assess the business necessity of the plugin, evaluate if it is exposed to the internet, and coordinate with your technical team to plan for updates or removal.

References