CVE advisoryCRITICAL
CVE-2025-11391
WooCommerce Product Addons Plugin Arbitrary File Upload Vulnerability.
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A vulnerability in a WordPress e-commerce plugin allows unauthenticated attackers to upload arbitrary files due to missing validation, potentially enabling remote code execution. This affects sites using the paid version of the software.