PT-2025-38123 · WordPress · Storeengine

Ryan Kozak

·

Published

2025-09-17

·

Updated

2025-09-17

·

CVE-2025-9216

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions StoreEngine versions up to and including 1.5.0
Description The StoreEngine WordPress plugin is susceptible to arbitrary file uploads due to the absence of file type validation within the import() function. This allows authenticated attackers possessing Subscriber-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update StoreEngine to a version beyond 1.5.0.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9216

Affected Products

Storeengine