PT-2025-33976 · Elextensions+1 · Reachship+1

Phat Rio - Bluerock

·

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2025-53213

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping versions through 4.3.1
Description: An unrestricted file upload vulnerability exists that allows the use of malicious files. This issue impacts e-commerce platforms utilizing the affected plugin.
Recommendations: Disable the plugin until a fix is available. Tighten upload restrictions to prevent the upload of dangerous file types.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-53213

Affected Products

Reachship
Woocommerce